Trojan/Malware infestation. Please Help! Logs attached!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mdb31483, Feb 6, 2007.

  1. mdb31483

    mdb31483 Private E-2

    Hello, I am having an extremely hard time removing some Malware/Trojans from my computer. I have followed all the scanning, safe-booting, and preparation tips listed in the READ & RUN ME FIRST Malware Removal Guide before posting my problems. I have spent literally about 10 hours trying to get rid of the viruses/spyware/malware and eliminated a couple problems but some will not go away. This is the worst infestation I have personally ever seen. At first my computer ran fine. Now it is extremely slow and my dvd drive won’t work as of today. Here is what my various tests showed and resulted in:

    Trend Micro-Cillin (my default virus protection):
    When the virus first hit it detected it but could not clean, delete, or quarantine it. The original file was: expl_execod.a - Now when running a Trend full scan it doesn't pick up any viruses or anything. I have real-time scanning enabled and it occasionaly warns me about various Trojans trying to load and it quarantines all of them except for Troj_Purity.r and TROJ_DLOADER.HBJ

    Spybot-Search & Destroy:
    It detects Smitfraud-C.Toolbar888 When I click Fix selected problems it says it cleans it, but upon restarting the computer it is back again.

    CounterSpy:
    Results attached below. Files come back after computer restarted.

    BitDefender:
    Results attached below.

    Panda ActiveScan:
    Results attached below.

    XoftSpySE:
    This scan finds: Troj/Agent

    software\microsoft\windows nt\currentversion\winlogon\notify\winbjt32\dllname
    software\microsoft\windows nt\currentversion\winlogon\notify\winbjt32\startup
    software\microsoft\windows nt\currentversion\winlogon\notify\winbft32\shutdown

    I remove the files above via XoftSpySE and upon restart of computer they are back again.
     

    Attached Files:

  2. mdb31483

    mdb31483 Private E-2

    I also must thank any who help in return.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please run this: Virtumonde aka Trojan Vundo Removal and attach the requested log. Then continue onto the below!

    You did not attach the log for GetRunKey; however, before doing that, you must make sure you are following the directions on the download pages for ShowNew and GetRunKey. The log you posted for ShowNew shows that the program was not run properly. Normally this means it was not installed properly per the instructions. Please follow the directions and also take note of the possible error messages, and then attach logs from ShowNew and GetRunKey.

    Then also attach a new log from HJT.
     
  4. mdb31483

    mdb31483 Private E-2

    Hello,

    Sorry about that. I have corrected the problem and the proper files are attached. I cannot thank you enough for assisting or attempting to assist me!
     

    Attached Files:

  5. mdb31483

    mdb31483 Private E-2

    I am attaching an updated HJT logfile. I got rid of everything, it appears, except for the Win32.Klone.g Trojan.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not pay attention to step 0 where we requested that you not use MSconfig to control startups. You must select Normal Startup as requested. If you don't want all those items to load at startup, decide if you need the software that is loading them. If not, then you should uninstall the software or at least change its settings to not load at startup. MSconfig should not be used for long term control of startups like this. If you cannot change the settings of the program and you never need the startups, the items can be removed from the registry using HJT and then you will not need to use MSconfig to control them.

    Also you did not do step 2 of the READ ME. At least not properly.

    Please correct the above to items but don't attach new logs yet.

    Now download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\My Various Programs\CounterSpy
    C:\Documents and Settings\Matthew D. Brill\Local Settings\Application Data\Sunbelt Software

    Continue by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winbjt32.dll once and then click the kill button. After you have killed all of the winbjt32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    ssfygifr.dll

    Next double click on explorer.exe and again click once on each instance of winbjt32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    ssfygifr.dll

    Next double click on iexplore.exe and again click once on each instance of winbjt32.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    ssfygifr.dll

    Now just exit Process Explorer.


    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\msvcrtd.exe
    C:\WINDOWS\system32\ssfygifr.dll
    C:\WINDOWS\system32\winbjt32.dll
    C:\WINDOWS\system32\wqyitgqq.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Feb 7, 2007
  7. mdb31483

    mdb31483 Private E-2

    Hello,

    After following your steps it seems to be running good. That Trojan is no longer detected. I used a bunch of different scanners and nothing is detected. The internet and computer run fine now. My dvd drive still seems a little screwy and I am going to check into that in a few minutes here and see whats up. I must thank you extremely for helping me with this problem. I was very much dreading the fact that I may have had to reformat and lose all my info. (no external drive for laptop to backup files) THANKS AGAIN! Here's the logs now for the heck of it.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Microsoft security update service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastemsupdate into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    After reboot I recommend that you verify that ALL functions of your TrendMicro program are working properly. It does not appear to be installed properly. So things that should show in your HJT log (like services to mention only one) are not showing. I would suspect that you may need to uninstall, reboot (don't skip the reboot), and then reinstall.

    After doing all of the above attach a new HJT log.

    Is everything still working OK?
     
  9. mdb31483

    mdb31483 Private E-2

    Hello,

    I ignored my Trend files in HJT. I guess that would be why you didn't see them. I took them out of the ignore box so you can see. Everything seems to be working great now. The dvd drive is reading cdroms now. I need to see if it is going to backup movies fine. Thanks again for the help.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's a feature of HJT that you must always remember to turn off when coming form help. Otherwise it will always lead to confusion.

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds