can not delete/remove some Trojans

Discussion in 'Malware Help (A Specialist Will Reply)' started by Qmis, Sep 14, 2012.

  1. Qmis

    Qmis Private E-2

    I followed the Malware Removal READ & RUN ME FIRST thread but I still get pop-ups for contingent trojan virus. Also, my anti-virus (Eset NOD32) keeps telling me that there are 3 files that need to be deleted:
    1st is located in C:/Windows/System32/services.exe <== can't be deleted
    2nd is C:/Windows/assembly/GAC_64/Desktop.ini <== says it will be deleted after restart but after restart is still there.
    3rd C:/Windows/assembly/GAC_32/services.exe same as the 2nd.
    I changed my anti-virus just yesterday so I have no idea how much time has passed since the invasion so I can not really say. The only disturbing fact that I noticed is that I see the "Desktop.ini" file in most of my folders, aside from that I don't have any other problem.


    Here are and the files that are asked to be attached:
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [RUN][ROGUE ST] HKLM\[...]\Policies\Explorer\\Run : 30320 (C:\PROGRA~3\LOCALS~1\Temp\msmieevbt.exe) -> FOUND
      [RUN][ROGUE ST] HKLM\[...]\Wow6432Node\Policies\Explorer\\Run : 30320 (C:\PROGRA~3\LOCALS~1\Temp\msmieevbt.exe) -> FOUND
      [HJPOL] HKLM\[...]\System : DisableTaskMgr (0) -> FOUND
      [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
      [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
      [HJPOL] HKLM\[...]\Wow6432Node\System : DisableTaskMgr (0) -> FOUND
      [HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
      [HJ] HKLM\[...]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND
      [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
      [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
      [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
      [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.

    Now click the Files/folders tab and locate these detections:


    • [ZeroAccess][FILE] @ : C:\Windows\Installer\{1afc50f7-4aa0-be7e-18f1-e6d19ca6a08b}\@ --> FOUND
      [ZeroAccess][FOLDER] U : C:\Windows\Installer\{1afc50f7-4aa0-be7e-18f1-e6d19ca6a08b}\U --> FOUND
      [ZeroAccess][FOLDER] L : C:\Windows\Installer\{1afc50f7-4aa0-be7e-18f1-e6d19ca6a08b}\L --> FOUND
      [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_32\Desktop.ini --> FOUND
      [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini --> FOUND
      [Sig - ZeroAccess][FILE] services.exe : C:\Windows\system32\services.exe --> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Rescan with HitmanPro, when it finds services.exe - Virus, allow it to Replace by clicking the down arrow next to the detection and choosing Replace.
    Choose to Delete these files if they are detected:


    • C:\devdll.dll
      C:\Users\Pontikaki\AppData\Local\Temp\01b8a8a6.exe
      C:\Users\Pontikaki\AppData\Local\Temp\02b94b02.exe
      C:\Users\Pontikaki\Downloads\DX10\asx-dmc4_dx10.exe
      C:\Windows\assembly\GAC_32\Desktop.ini
      C:\Windows\assembly\GAC_64\Desktop.ini
      C:\Windows\Installer\{1afc50f7-4aa0-be7e-18f1-e6d19ca6a08b}\@ (ZeroAccess)
      C:\Windows\Installer\{1afc50f7-4aa0-be7e-18f1-e6d19ca6a08b}\L\ (ZeroAccess)
      C:\Windows\Installer\{1afc50f7-4aa0-be7e-18f1-e6d19ca6a08b}\L\00000004.@ (ZeroAccess)
      C:\Windows\Installer\{1afc50f7-4aa0-be7e-18f1-e6d19ca6a08b}\U\ (ZeroAccess)
      C:\Windows\Installer\{1afc50f7-4aa0-be7e-18f1-e6d19ca6a08b}\U\00000008.@ (ZeroAccess)

    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    Use windows explorer to find and delete:
    C:\Users\Pontikaki\AppData\Roaming\79g7gg.sys

    Attached is bfe.zip

    Inside is:

    • bfe.reg


    Extract bfe.reg to your desktop.
    Double-click bfe.reg and allow it to merge into the registry. If you get a "successfully merged into registry" type of message, reboot your PC and see if you can turn on BFE, or if it is already turned on.

    You can run these commands from the command prompt.

    • net start bfe
    • sc qc bfe


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * HitmanPro log
    * RogueKiller log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. Qmis

    Qmis Private E-2

    First of all, I would like to apologize for the late notice, I left due to family reasons and didn't have any means to communicate with the forum.
    This pc is shared by two people, me and my roomate, who took the initiative and did a format on this pc. I am at fault too for not letting him know that I was waiting for help so, I would like to apologize also, for the incovinience I have caused. Thank you very much for your help.
    have a nice day.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry to hear that. Hope all is well.

    No problem. At least you are malware free now. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds