Torjan,malware,or virus? help please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by GoodZwell, Jan 3, 2014.

  1. GoodZwell

    GoodZwell Private First Class

    HI guys.

    Ok running an old Asus desktop. Pentium 4 Win XP Pro Service pack 3.

    Been running all the stuff you guys sudjest to do before posting. Now I can't remember how I came accross my problem other then to say the computer seems to lock up for no reason. So I ran a scan with AVG and was told I have a trojan. So then I decide to install Trojanhunter5.5 and it tells me I've got a whole bunch of nasty stuff on my desktop. ew... So I know it's an older machine but used to run quite well. Now when the wife trys to move pictures from one folder to another it locks up. Any who. I have some jpegs of what Trojanhunter told me I had and a bunch of other logs from the stuff I ran from this site. Trojan hunter says I have: trojan backdoor.generic17, zbot 14717, Genome.2160, agent.11940, tredval.240, mixor 106, worm.bobic.104.

    oh and I tried to login to my hotmail account and it would load the page.

    Ok now I'm scared.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So where are the logs we request?

    Why are you running these? Our procedures do not request this and they specificially state that once you start our cleaning process that you should only do what we request and nothing else.

    Non-malware problems can be posted in the Software Forum. If you have worries/suspect malware is causing you probems then run the READ & RUN ME FIRST and attach the logs we request.
     
  3. GoodZwell

    GoodZwell Private First Class

    Sorry I'm not here for an argument. I thought I was following the proper procedures as it is stated in your READ before posting section. [/QUOTE]
    Now if you are ready to continue with malware removal:
    Complete ALL of the below steps including the specific malware removal cleaning instructions for your Windows Version. [/QUOTE]

    So that's what I did.
    I didn't post any logs because I was not asked to.
    I was running those programs as per Read and preform before asking for help.

    Sorry If I was mistaken and didn't follow the proper instructions.


    Here's what I've found if you are still interested.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah but you were. See step 3 of the Windows XP cleaning procedure again. ;)

    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    Java(TM) 6 Update 37


    Now install the current version of Sun Java from:

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\RECYCLER\S-1-5-18\$c859274165143a7937c07fab56cb7816\@
    C:\RECYCLER\S-1-5-18\$c859274165143a7937c07fab56cb7816\L
    C:\RECYCLER\S-1-5-18\$c859274165143a7937c07fab56cb7816\U
    C:\RECYCLER\S-1-5-18\$c859274165143a7937c07fab56cb7816
    C:\RECYCLER\S-1-5-21-1177238915-823518204-682003330-1003\$c859274165143a7937c07fab56cb7816\@
    C:\RECYCLER\S-1-5-21-1177238915-823518204-682003330-1003\$c859274165143a7937c07fab56cb7816\L
    C:\RECYCLER\S-1-5-21-1177238915-823518204-682003330-1003\$c859274165143a7937c07fab56cb7816\U
    C:\RECYCLER\S-1-5-21-1177238915-823518204-682003330-1003\$c859274165143a7937c07fab56cb7816
    C:\Documents and Settings\GoodZ2\Desktop\*Defogger.exe
    C:\Documents and Settings\GoodZ2\Desktop\*RogueKiller.exe
    C:\Documents and Settings\GoodZ2\Desktop\*mb.exe
    C:\Documents and Settings\GoodZ2\Desktop\*tdsskiller.exe
    C:\Documents and Settings\GoodZ2\Desktop\*HitmanPro.exe
    C:\32788R22FWJFW
    C:\Combo22Fix
    C:\Qoobox
    C:\_OTS                                              
    C:\Documents and Settings\GoodZ2\Local Settings\temp\*.*
     
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{23088cf8-eaf8-4bb3-a251-9ba61557ac75}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{27b23de2-f88c-4279-8931-59ab0a037e68}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{23088cf8-eaf8-4bb3-a251-9ba61557ac75}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{27b23de2-f88c-4279-8931-59ab0a037e68}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. GoodZwell

    GoodZwell Private First Class

    Ok installed OTM copy and pasted the code you gave me. AVG said it was a known Trojan and that I shouldn't run
    it but I allowed it to. Restarted after promted to, then the computer hung on reboot at the posting page for
    Asus. At the bottom of that screen it says " Press Del to orun Setup, or Press TAB to deisplay BIOS POST
    message", but it does nothing when I try to do that. So I'm going to hold on the power button to restart the
    computer. RRR.....

    OK rebooted and am getting the same thing, HUNG on Asus start up screen. So I guess my
    next question is. Did you just get me to download a program that was actually a Trojan and screwed me? I've
    googled MajorGeeks and there is nothing there that says you guys are not lagit. I've used you guys before and
    never had a problem but I'm not as computer savie as I'd like to be. So now I have a computer that won't
    boot. ARRRRGA....Ok rebooted again using the reset button this time. at the asus screen I waited for about
    three mins or more then hit DEL it seemed like it was going to boot but hung again on the "American
    mEGATRENDS" WINDOW. Posted the USB devides, Auto-detecting the Sec Master ATAPI CD-Room and the 3rd adn 4th
    IDE hard Disks, Sec Master: TSSTcorp CDDVDW TS-H662A Uo00, then Auto -detection the USB MAS STorage devices
    Device #01 : Then it hung again and I've been waiting now at least 7 minutes for it to continue. Going to
    reboot again. Ok this time I've unpluged the usb drive I had plugged in and it booted but goes through the
    set up like I'm trying to set up a raid array but that is I think it's usual path. in the past I've tried to
    set up a raid but was unsucsessful, along with my spelling. ;)


    Damit, I forgot to run the OTM from desktop, I ran it from the usb drive I had to use because I couldn't login
    to Majorgeeks on the infected computer. Should I run OTM again, properly this time?

    So since I ran OTM from the usb drive I found the files it made on the usb drive and will include them.
    Sorry it slipped my mind when I was trying to follow my instructions. "ADHD" my bad.

    Ran MGlogs attaching files as per request.

    Am able to now login to MajorGeeks but not hotmail. sending error jpeg.

    Thanks for your help. much appreciated. :)
     

    Attached Files:

    Last edited by a moderator: Jan 5, 2014
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Obviously AVG is wrong.

    Absolutely not.

    Okay so I'm having a problem understanding the outcome now. Are you having a problem booting your PC now? You shouldn't be. All we did is remove some junkware and some leftovers from a ZeroAccess infection.
     
  7. GoodZwell

    GoodZwell Private First Class

    Hi,

    Sorry not trying to confuse you. When I ran OTM and tried to reboot the computer it wouldn't post, it would hang on the Asus Start up screen but after three attempts it finally started winXp service pack 3. So I will start it up again today and take some pictures of that process. It might be the way bios is set up because of me trying to set up a raid a few years ago, there might be a setting in there that I had to use and don't need any longer as I don't believe it's set up as a "raid" any longer. Oh and I'll include a screen shot of the virus/malware AVG is telling me this computer is infected with.

    So I guess the only thing I can tell you for sure is I can't login to Hotmail at all, it won't even load the login page. I'll get back you on it later today. Thanks for you help and I'm sorry about thinking you guys weren't legit, sometimes I'm a little paranoid. :eek
     
    Last edited: Jan 6, 2014
  8. GoodZwell

    GoodZwell Private First Class

    AVG report
    don't think I can send attachments from this problem computer. nope. I'll send it via my laptop
     
    Last edited: Jan 6, 2014
  9. GoodZwell

    GoodZwell Private First Class

    AVG report sending in a different file format. da....
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this old information or current infomation? Your last MGlogs.zip file does not show those file in your temp folder. Only the below were seen
    Code:
    "C:\Documents and Settings\GoodZ2\Local Settings\temp\"
    adobearm.log   2014-01-05         921  "AdobeARM.log"
    armui.ini      2014-01-05      191518  "ArmUI.ini"
    DIV1.TMP       2014-01-05              "div1.tmp"
    HSPERF~1       2014-01-05              "hsperfdata_GoodZ2"
    javade~1.log   2014-01-05          34  "JavaDeployReg.log"
    JRT            2014-01-05              "jrt"
    jrt.txt        2014-01-05        2169  "JRT.txt"
    jusched.log    2014-01-05        2679  "jusched.log"
    WPDNSE         2014-01-05              "WPDNSE"
    You need to empty your AVG Virus Vault to get rid of the old info.

    You can post about hotmail problem in the Software Forum. Possibly you blocked something in your firewall or AVG.
     
  11. GoodZwell

    GoodZwell Private First Class

    I guess that was old info as the date for the most recent AVG infection shows Jan 1st. 2014.


    I'll post there for hotmail help.
    Thanks for you help. Happy belated new year. :)
     
  12. GoodZwell

    GoodZwell Private First Class

    for got to post this. It was done before I contacted you guys.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But again this is old info. What we care about is the present status. Are you having any problems are than your hotmail issue?
     
  14. GoodZwell

    GoodZwell Private First Class

    HI.
    I realize that was old news but wanted to know if that's what we were trying to remove and if it was were they trojans?

    yes I'm am still unable to login to Hotmail with Internet explorer but can with firefox. so the issue must be with internet explorer some how.

    Thanks again for you support. :cool
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that is not what we were removing and they were not trojans.


    Why do you have the below setup?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.1
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.1:80


    Also I had noticed that your Windows Firewall was broken. You should try doing the below which may correct this and some other issues that could exist.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 10, 2014
  16. GoodZwell

    GoodZwell Private First Class

    Didn't know I had this and I don't even know what it is? :confused

    Will post later what you requested I do.
     
  17. GoodZwell

    GoodZwell Private First Class

    Computer seems to be running ok but still can't login to Hotmail with INternet Explorer.

    here's the MGlogs
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a malware problem as stated earlier. You should try disabling or uninstalling AVG to see what happens. Also try Resetting Internet Explorer back to defaults.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  19. GoodZwell

    GoodZwell Private First Class

    HI, soirry for the delay in getting back to you, been busy.

    Ok disabled AVG and ( i think) reset internet explorer, as the instructions link doesn't tell you where to find this feature, ie. control panel, which is where I found internet options. Tried to load Hotmail and still no luck. Get this error:

    Webpage error details

    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2; .NET4.0C)
    Timestamp: Fri, 17 Jan 2014 15:42:54 UTC


    Message: Script error
    Line: 0
    Char: 0
    Code: 0
    URI: https://auth.gfx.ms/15.500.24000.00/Login_Core.js




    Any who it seems like this computer is running a little better and not bogging down as much. Thanks for the help, you Rock. :)


    Will commence on removing the programs I installed to remove the malware.
     
  20. GoodZwell

    GoodZwell Private First Class

    Ok in step five of removing the restore points.


    5: To re-enable System Restore, follow steps 1-3, but in step 3, click to clear the Disable System Restore check box.

    There is no CLEAR Disable system Restore Check Box any where on that window. ??
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions are telling you to uncheck the check box that you checked in step 3.
     
  22. GoodZwell

    GoodZwell Private First Class

    Thanks for all your help Chaslang, you are the best! :)
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds