Big help needed with Trojan virus!

Discussion in 'Malware Help (A Specialist Will Reply)' started by steveo457, Sep 29, 2006.

  1. steveo457

    steveo457 Private E-2

    Hi, I have used major geeks before to solve a Lop.com toolbar virus, and I was extremely pleased with the knowledge and helpfullness of you guys and gals so I was wondering you can help me out some more?
    I'm not sure if I have a problem but I've got a sneaky feeling I might have something "attached" in my PC. I keep getting e mails from firms saying that they have detected something that has attached itself to my comp and is acting as a sever, if thats the right word, to send e mails to all my address book. I have ignored these, scan your computer for free, E mails and just delete them, but now I keep getting messages from addresses saying Mail delivery failed etc etc. I have never sent any e mails to these people!!!!
    I do genuinely clean my PC with the excellent programs from your site and am up to date with my Firewall's and virus. my PC does run a bit slow at times and always think this has something to do with some little bugger mesing with my PC.
    Any help and advice would be very very very much appreciated.
    Keep up the excellent Work
    Peace
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Stevo

    To fully help you and us to find whats on your PC that could be causing this, I would advise you to start first with the first steps guide I will post below, once you have followed the steps in order as described and then attached the requested logs, we can then see what the malware infection is and then the malware experts here can post some further sets of instructions for you to mop up the remaining components of the infection.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. steveo457

    steveo457 Private E-2

    Hi, Thankyou for the quick reply.

    I have done all the mentioned steps in the Read me first link. I downloaded all mentioned programs and scans and completed all the steps.
    the only one I had trouble with was the step where I had to enable all hidden files and Folders. For some reason whenever I tried to open the tools files to do this the file just froze and all i saw was a blank page. I tried again and again but it just wouldn't respond. I have previously selected to view all hidden files from a previous cleaning process so I'm pretty certain that It is selected anyway.
    All the steps were successfully completed apart from the bitdefender scan. it wouldn't initilize the scan for some reason so I just done the Panda Active scan. this completed. I have added A hijack this Log and the log for the runkeys.txt and the newfiles.txt as per requested. I think I have done all that was asked and look forwrd to hearing from you.

    regards steveo457
     

    Attached Files:

  4. steveo457

    steveo457 Private E-2

    heres the panda active scan (i think)
    regards
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! That is just an intermediate temp file from ShowNew. The Panda log is normally named activescan.txt. You need to attach it. Panda often shows many things that other scans do not pick up.

    Please try Bitdefender online scan again and make sure you are using Internet Explorer. Also update your Sun Java version first as requested in the READ ME. Your version is way out of date.
     
  6. steveo457

    steveo457 Private E-2

    Hi, I can't find the Panda scan so I will do it again and post the results later on.
    I have done the bitdefender scan but after 14 hours it is still going. It has only got two seconds to go (and it's said that for the last 7 hours) but it will just not finish. Surely it should be done by now? It has found a lot of infections, the main one called W32.Alcra.B. like I say the scan is completed but it won't finish. What is going on?
    I've tried updating my Java platform too but when I click on the download button, I just get server not found page on all the download site addresses. I also have a new problem with my Norton internet security suite, when I try and open it, the whole thing just freezes and fails to open and I have to close it with ctrl+Alt Del. I am totally stuck on what to do next, why isn't the scan finishing. I've even tried cancelling it and starting again but it just doesn't finish.
    please advise. I'll keep trying and post the logs as soon as I can.
    regards
     
  7. steveo457

    steveo457 Private E-2

    The bitdefender scan is showing that it has 33 files left to scan, but as I said before it has been showing this for the last 7 hours. i'm stuck
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see any problems in your logs! If Bitdefender was finding W32.Alcra.B, where was it finding it? Was it only in your System Restore folder? Alcra.B is often picked up and spread by using P2P programs which you appear to be using (I saw a few in your ShowNew log). I'm not sure why Bitdefender was not completing the scan, but sometimes it can take a very long time to run. It depends on how fast your connection is, how many files are on your PC, and whether you are trying to do other things (especially running other scans) at the same time.

    When you tried to get the new Sun Java version installed, did you download the installation file and then run it afterwards from your PC. Or did you try to Run the installation direct from the internet.

    Your original problems about emails sound more like spam attacks. This just means that spammers know your email address. Based on your log
     
    Last edited: Oct 4, 2006
  9. steveo457

    steveo457 Private E-2

    Hi, I have succesfully completed the bitdefender scan but I didn't read your messages regarding how to upload it. I didn't save it so it doesn't show all the clean files. i am going to re do it and post it for you. I think I definately have some sort of problem as last night I totally lost all windows. All I had was a blank wallpaper screen and then the pc reset. When it booted up again it went straight to a blue Windows XP screen and started running through a scan disk check. It was saying stuff like- File system NTFS check, veryifying files, verifying index's and then started deleted corrupt sttribute sections/record orphan file/error in index $I30. Then after all this it went throgh the same process as before but stating that it was correcting all above. very strange as I have never ever had this before. When it did finally reboot, I had lost my internet connection and had to phone up my provider and they reset it or something. Also my up to date Norton Anti Virus software had been disabled and was saying it was out of date. I am currently subscribed till 2007 with both virus and firewall with norton.
    This is all very very strange. Have you found anything in my logs that would have caused this massive major crash. I'm getting quite worried that I have something. As I said I will do the bit Defender scan again and post it as I really need some advice on this one. Is there any other advice you could give me in what I could do to stay absolutely clean and virus free.
    thanks again for your help big time, it is very very much appreciated.
    I'll post that log ASAP.
    regards
     
  10. steveo457

    steveo457 Private E-2

    Also I have just succesfully downloaded and am running the java 2 platform. Will do the scan and post the results for you.
    regards
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't need a log from Bitdefender showing clean files, I only need one that shows infected files. And if they are in System Volume Information, that is just System Restore which can be cleaned by toggling System Restore as mentioned in the READ ME step 9.

    Your problems may not be malware. At least not all of them. However let's give the below a run:

    Download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.
     
  12. steveo457

    steveo457 Private E-2

    Hi, I have finally been able to complete the bitdefender scan. I thought you might want to look at it while i do the blacklight scan. I will also log these results when it finally finishes. It seems to have stopped or got stuck, but i'll persevere with it. I wasn't sure if you wanted to see the bitdefender log so I just posted it anyway. My norton protection does keep picking up the virus that i think is responsible- Win32.Alcra.B and similar variants with a few different letters. It deletes some of them automatically, but others like the mentioned above, it says it cannot access file and cannot delete. then it sorta freezes a bit. It has found the virus's mostly in the temp files I think. I am also getting even more mail delivery failed messages. It's only strange because i have lokked at the messages properties and most are a different e mail address but with the back end of my e mail address added at the end, example 12345@my e mail address.

    Thanks again for your help, very much apprecaited,

    regards
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I stated, most of your problems found by Bitdefender are in System Restore. Toggle System Restore as stated in the READ ME. See step 9

    The others you just need to cleanup manually by:
    1) Emptying your Norton Quarantine
    2) Delete the reference email message from you inbox.
     
  14. steveo457

    steveo457 Private E-2

    Hi, I've toggled my System restore as per requested. I've done a few more scans like spybot, norton etc. I've also deleted my entire Inbox and cleared out my outbox and deleted files and so on. Things have improved but I do still get major system stalls when opening new windows, or applications. some last a good minute or so. Start up is extremely slow too.
    I'm still getting the E mail delivery messages. about 5 a day.
    I have tried several times to complete Blbeta scan but it starts fine, then gets stuck on my Local settings folder and will not go any further. I left it running all night and it didn't move from the same folder in all that time. Do you think something could be wrong with this folder? I've tried looking at the folder but, like a few others it is not selectable. the icon is slightly faded and you can't open it.
    I have enclosed the scan report anyway, just so you can see how far it is getting.

    hope you can help.

    Ragards
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This may not be malware. It could be problems with your OS or possibly your hard disk has errors. Have you run an error check on the drive recently?

    Sounds like spam to me!

    Also sounds like an error on your hard disk.
     
  16. steveo457

    steveo457 Private E-2

    How do i run an error Check? If it does find errors can it automatically fix them or do I have to buy a new hard drive? Things have improved dramatically now. system is fast and jumping from one application to another has improved. I'm still getting the email messages. Do you reckon these are just Spam? Ugggh I bloody hat spam. Whats the point in causing someone loads of grief? Just go back to your little spam hole and come up with some better idea to get ahead in life!!!!!
    thanks again for your help, it is very much appreciated. you do a sterling job.
    regards and all the best
    Steveo
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If everything is working OK now then you don't need to do this. Based on your last message it sounds like things are fine. At any rate, you would just open up Windows Explorer and right click on the hard disk drive and select Properties, Tools, and click the Check now box in the Error-checking section of the form. Then you select the two check boxes on the next Check disk options window and then click Start.


    Yes that is what a said a couple of times now.


    If you are not having any further problems, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds