Help... Trojan.downloader and Spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by emalvick, Apr 20, 2007.

  1. emalvick

    emalvick Private E-2

    I have bitdefender and it recently found a trojan: trojan.downloader.small.bfi.

    It is unable to quaranteen or delete the file, and when I tried to boot into safe mode (thinking I might be able to get rid of the file that way), my computer won't log in, hanging at agp440.sys.

    So, I started using my own Spybot Search and Destroy program and Ad-aware only to find that Ad-aware hangs on the file that has the virus.

    Well, that led me here. I ran through the Read & Run me first routine as much as I could.

    Spybod S&D and Counterspy were both run and both didn't find anything.

    I then tried to run the Bitdefender Online Scan, but it wouldn't run. The file attached is from my home copy of Bitfender, which I am able to run. That shows the trojan.

    I then ran the Panda Active Scan, which found a lot of Spyware but not the trojan that I could see). It couldn't get rid of any of it, but maybe I could delete the files it showed? I did run the CCleaner, which I thought would delete all the cookies.

    The other logs are attached in the following email (GetRunkeys, ShowNew, and Hijack this).

    Can you suggest any course of action?

    Thank you
     

    Attached Files:

  2. emalvick

    emalvick Private E-2

    Here are the other log files..

    Thank you.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You did not run what we requested in step 6 for BitDefender Online scan. You attached a log from the BitDefender 9 Antivirus which you already had installed. The online scan often finds things that that the full antivirus application does not find. You should follow the directions in step 6 and run the BitDefender online scan and attach a log from it. However all that being said, if all you are concerned with is the file that your BitDefender 9 Antivirus found, which was the below:

    C:\Documents and Settings\Administrator\Local Settings\Temp\hq21j6eo.rar


    Then just delete the file but it should already have been deleted if CCleaner was run before BitDefender. Look for yourself! The file is probably gone.


    You should uninstall CounterSpy now since it is no longer required.
     
  4. emalvick

    emalvick Private E-2

    As I mentioned in the initial post, I cannot get the file to remove. If you look at the log I posted, it states that the move and quarantine have failed.

    As I also mentioned, for some reason the Bitdefender online scan will not run on my computer (and the Panda Scan does work). I did load the required activex controls... It keeps asking me to everytime I try and seems to fail.

    The reason I posted the first time was because I cannot get rid of the file listed (it has been there every step of the way). CCleaner, my own deletes, and Bitdefender seem to be blocked from accessing this file.

    I also cannot get my computer to boot into safe mode, which might be related, I don't know.

     
  5. emalvick

    emalvick Private E-2

    Should I take this to mean that you see nothing else wrong with the logs? I really want to be able to get rid of that file, but I also want to be sure there aren't any other major problems. I'm not convinced that file (trojan) is the only thing preventing me from booting into safe mode. I don't like not being able to get into safe mode.

    It also bothers me that I cannot get the Bitdefender online scan to run when the installed program runs on my computer.

    Erik

     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And as I said, Ccleaner already removed it since it was in your Temp folder and that is part of what CCleaner cleans. Look for yourself. Do you see the file anymore?



    Not necessarily malware. And you don't really show any.

    The only other file of question (and that is unknown ) was in your last newfiles.txt log was:
    Code:
    "C:\Documents and Settings\Administrator\Local Settings\Temp\"
    uobihi~1.exe  Apr 19 2007        2560  "UOBIHIJXE.exe"
    You should be able to manually delete this or just run CCleaner with ALL other applications and browsers closed to remove this.


    Does Norton SystemWorks 2005 Premier include an antivirus??? As far as I know it does. That would also mean you are violating step 3 of the READ ME by having BitDefender 9 installed.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's correct.

    As stated, it is already gone.

    Not malware. See: http://support.microsoft.com/kb/324764
     
  8. emalvick

    emalvick Private E-2

    CCleaner does not delete that file. It is there. This is what I've said in my messages. It is there as plain as I can see.

    That exe file is one I don't know about, and anything that was put there yesterday is unknown to me as the only thing I did is run the scans outlined in the readme. The Panda Active Scan took 4 hours and the other hours of my day were spent at work.

    As for the antivirus, I uninstalled the Norton Antivirus part of system works because I didn't like how it worked, and the subscription ran out. I then bought Bitdefender. I kept the remaining part of NortonSystem Works because I wanted Ghost for backups, but only one Anti-virus on the computer.

    I just want to be able to get rid of that file, and it is assuring that you don't see much else. I am guessing this one file, whatever it is, may be blocking me from getting into Safe Mode?

    Erik

     
  9. emalvick

    emalvick Private E-2

    I just wanted to reiterate that while CCleaner is supposed to get rid of all temp files, it will not get rid of that one file. I'll try to post a screen shot of that folder / directory, later this afternoon... I'm not at that computer at the moment.

    Erik
     
  10. emalvick

    emalvick Private E-2

    Hey... by the way, thanks for that link. I'll give that a try, and it is a little reassuring to know that might be a separate issue. I generally feel like I do ok with keeping viruses off my computer and Bitdefender has worked excellent for the most part (except this one file), which it does flag as a virus.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then I would have to assume the file date is old since your newfiles.txt log shows only the below.
    Code:
    "C:\Documents and Settings\Administrator\Local Settings\Temp\"
    glauka~1.log  Apr 19 2007       16780  "GlaukaCommDll.log"
    JUNIPE~1      Feb 22 2007              "Juniper Networks"
    uobihi~1.exe  Apr 19 2007        2560  "UOBIHIJXE.exe"
    What is the date of this file?

    Try running the below! Again make sure no browsers or other applications are running.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Did that get it? If not, we will use Pocket Killbox to try and remove it. If the file system is corrupted, then it will not be able to remove this file so easily.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not address the question about Norton System Works and its antivirus.
     
  13. emalvick

    emalvick Private E-2

    As I stated, I uninstalled its antivirus. Norton System Works is just a container for the Norton Antivirus, Ghosts, the Norton Firewall, etc... I didn't want Norton Antivirus anymore, so I uninstalled that part of Norton System Works and put Bitdefender on my computer. Therefore, Norton System Works does nothing in terms of antivirus... Believe me, I can tell. Removing that part of the program has increased the speed of my system quite a bit.

    I'll get back to you on the other parts including the date, although I do know it is 2006... Strangely, I've used CCleaner quite a bit in the past, and that file has not been there until the past week.

    I'll try the other program when I get home, but I know when I go to the Cmd prompt and try to manually delete the file (del *.* [it's the only file in that folder]), it does provide an error on that file stating the system is corrupt. I could probably try and put that into a text file if it will help.

    Erik
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, sorry about that! I missed the fact that you had posted three replies. It is still rather stupid that Norton would require all of those processes to run just to have Ghost! Why isn't the only process that is necessary Norton Ghost? And why does it always need to be running? Are you actually always doing drive images every day?

    If the files system is corrupt, you more than like will not be able to remove the file using any of these tools. You need to fix your file system which is not a topic for this forum, but isn't that part of what Norton System Works is suppose to do (like chkdsk, scandisk, and also disk Error-checking).
     
  15. emalvick

    emalvick Private E-2

    I kept Norton System works for the Firewall and the other Recovery tools... In all honesty, I thought the inability to delete the file was due to the virus and that had something to do with my inability to get into Safe Mode.

    I don't do drive images every day, but I did one recently because I actually upgraded a hard-drive 2 weeks ago. Interestingly, that hard-drive did have errors via chkdsk. This one does not (I checked it before I found this forum).

    When I upgraded the drive, I ran a chkdsk on the old drive, imaged the disk, and then restored it onto the new disk using Ghost. The likely problem now is that a file on a corrupt sector got backed up into the image file and ended up on the hard-disk (which happens to be this file). Oddly, looking at the old Bitdefender logs, this file had shown up, but it was always stating that the virus was blocked, and I hadn't paid attention to the fact that it wasn't being deleted.

    I'm not sure where to go from this point, and if you have any suggestions (even to another forum), I'd appreciate it. I'll try the Norton System Works restore disk too, as I actually forgot that I have that available.

     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is quite possible.

    Well actually you have your options set incorrectly anyway. Your first option was set to Quarantine and your second option (which is used when the first fails) is also set to Quarantine which is basically like not having a second option. Your second option should be Delete. However for this file that may not work anyway if it is truly corrupted in the file system.

    The Software or Hardware Forum would be the next steps. You could also try booting to the Recovery Console and seeing if you can manually delete the file; however, normally when there is a corruption at the disk level, no deletion methods are going to work. The disk and or the file system need to be repaired in these cases.
     
  17. emalvick

    emalvick Private E-2

    Well, I'll fix the bitdefender settings... Of course, the fact that it can't quarantine the file (i.e. moving it fails) is related to it not being able to be deleted. I actually tried to manually delete because the moving wasn't working, which led to me finding that I couldn't get into Safe mode....

    Anyway, I am confident at this point that the hardware itself isn't corrupted as the new drive is probably just reflecting a hardware corruption in the original hard-drive. If that is the case, the file is corrupt, but probably the system (at least I am optimistic about this). I'll try a few things, and then post in that forum if needed (and follow this up here if the ATF thing worked).

    I'm trying to avoid a format as my system is getting quite old and the XP install disk I have predates SP1 even.

    Thanks for all your advice.

     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A possible solution could be to do a new image back up of your whole hard disk except for that temp folder (if Ghost gives you that flexibility). Then install the new image and recreate your temp folder manually.
     
  19. emalvick

    emalvick Private E-2

    Re: Help... Trojan.downloader and Spyware (fixed... thanks)

    I just wanted to give a final update on my situation and thank Chaslang for the advice and patience with my problems..

    As it turns out, the final problem was not a virus or malware as was pointed to me and eventually led me to look for drive problems. Well, upon looking at the file closer, I found the file was indeed corrupted by the file system. The hard-drive was fine as was the file system, etc...

    I was able to remove it using the Norton Systemworks Recovery Console... i.e. outside of windows. For some reason even the Windows Recovery Console would not let me have access to that file.

    Afterward, I had to turn off system restore as the corrupt file was also in the restore points. Once that was completed, I was able to run all the online scanners and my system scanners without any problems (and without any malware).

    My computer is now working well although I am still having problem getting the system to boot into safe mode (seems to be related to the AGP440 driver, but that is for another forum).

    Anyway, thank you again for the help (and for helping others). I actually installed a different firewall (I was using the standard XP firewall before) and now things are even running better for my LAN and my computer. This is a great site and great help.

    Thank you,

    Erik
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Help... Trojan.downloader and Spyware (fixed... thanks)

    You're welcome. I'm happy to hear you got it worked out.

    I gave you a link to look at in message # 7 related to this.
     
  21. emalvick

    emalvick Private E-2

    Re: Help... Trojan.downloader and Spyware (fixed... thanks)

    Yes... that link's suggestions didn't work, although upon some further looks it seems that the problem can be much worse than Microsoft will have one to believe. For some people, the only thing that works is uninstalling SP2 or buying a new video card. I'm not going to worry too much about it at this point as I don't want to uninstall SP2, and I don't feel like I should have to get a new video card... I might be able to roll back my current video card's driver to a previous point (which might explain why things have changed since it was upgraded not too long ago). Anyway, as I find more out, I'll probably post a thread on the software (or hardware if it seems to be video card specific) threads.

    Again, I'm just happy to have that corrupted file (and its imbedded virus) off my computer. By the way, that file (perhaps due to the corrupt nature) would change file dates every time I tried to delete it. I was paying close attention after your suggestions and information about the file date. There were times when the file date would show 10 years back. It was all very random (sometimes 10 years, others a few months, etc.)... no obvious pattern or trend.

    Erik
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Help... Trojan.downloader and Spyware (fixed... thanks)

    Well it's too bad that the simple fix from MS did not help you! This is not an uncommon problem as you have quickly found out. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds