Can't remove Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by soph4, Apr 23, 2011.

  1. soph4

    soph4 Private E-2

    I have caught a redirect virus that I have been trying to get rid off since 4/20. I have run through the entire "Malware Removal" Read me and it is still on my computer. Here are the details:
    -Initially AVG found Trojan Agent_r.XJ, but could only remove 2 of 4 infections.

    - SUPERAntipyware and Malwarebytes found nothing. However my computer would freeze every time I tried to save the logs, so I copied them (cut and paste) into a PDF that I will attach.

    - I could not turn off my firewall (windows) and got the message: "service cannot accept control messages."

    -ComboFix would start to load but crashed (BSOD) the computer every time.

    - Both RootRepeal and MGTools ran and I will attach the logs.​

    OK, the RootRepeal log is too big to attach (425 mb). I turned it into a PDF, but is still will not attach. Any Ideas?

    Beyond just fixing the thing my question is this... I now have dumped AVG and have not reset everything the malware removal file suggested. I still have the virus. Should I reset everything until I can get some help??

    Thanks,
    Soph
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F2 - REG:system.ini: UserInit=userinit.exe
    O2 - BHO: (no name) - MRI_DISABLED - (no file)
    O4 - HKUS\S-1-5-18\..\Run: [D1T2EUR7FZ] C:\Windows\TEMP\Wgr.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [D1T2EUR7FZ] C:\Windows\TEMP\Wgr.exe (User 'Default user')
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Users\Lil's\AppData\Local\Temp\

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. soph4

    soph4 Private E-2

    OK, so I can't get the analyze.exe will not open.

    I did right click and tried to "Run as Administrator", but I get the message: "the service cannot accept control messages at this time".

    Should I go on to the next step? (Avenger)

    Also, whenever I try to save these logs the computer freezes. This time instead of force quiting the program I waited it out and it unstuck about 5 minutes later. This is happening with other commands as well.

    Thanks for your help,
    Soph
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try logging into the Lil's user account in safe boot mode and see if you can complete the instructions. Even if you cannot run analyse.exe, just continue on anyway.
     
  5. soph4

    soph4 Private E-2

    Great!

    -Working in safe mode I did get the analyse.exe to work and I got the SUCCESS message. Although, when I tried to restart in order to get to safe mode the computer crashed (BSOD).

    -The Avenger also seemed to work but crashed at the reboot point (BSOD again). So I did not get the log file pop up. I assumed the log had been made and continued with your instructions.

    -The WINDOWS\TEMP file would not delete the following 2 files and said it "needs permission" to do so:
    C:\WINDOWS\TEMP\DF2BAB.tmp
    C:\WINDOWS\TEMP\DF1638.tmp​

    - Attached is the MGlogs.zip , but I can find no log for the Avenger. I don't think is was saved. Should I run it again?

    -Also, I still have gotten redirects and I get the blue screen crash when I restart or shut down.

    Thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Now download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  7. soph4

    soph4 Private E-2

    Thanks for getting back to this.

    MBRcheck came up with nothing. The log is attached.

    Tdsskiller would not load past 80%. I tried renaming and I tried dumping it and downloading it fresh. It still will not load.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need your Windows Vista boot DVD so that you can boot up to the command prompt to run TDSSkiller. Do you have your boot DVD?
     
  9. soph4

    soph4 Private E-2

    No, I don't have the Vista DVD. I do have the Windows 7 upgraded DVD, though, that i never installed. Will an upgrade do the trick?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It needs to be a bootable disk so that you can boot to the Recovery Environment.

    First move or redownload TDSSkiller and save it to your root folder so that you have C:\TDSSkiller.exe

    Then try create this disc: Vista and Win7 Recovery disc

    Once you have created it, go into the bios and set the cd/dvd drive to first boot device. Put the disc into the drive and reboot. You want to go into the Command Prompt to run TDSSkiller.exe as shown below.


    Now to get to the Windows RE. To do this, follow these steps:
    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Once you are at the command prompt type the below and hit the enter key
      • C:\tdsskiller.exe
    8. Then reboot your PC into normal mode and tell me how this all work and how are things working on your PC now?
     
  11. soph4

    soph4 Private E-2

    How do I save to the root folder?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just navigate to the c:\ folder to save it. Or you can move or copy it from your Desktop folder to the c:\ folder using Windows Explorer ( right click Start and select Explore to bring up Windows Explorer ).
     
  13. soph4

    soph4 Private E-2

    OK, I have done everything. So far I still have the redirect from links in a google search problem, but no tabs or windows have spontaneously opened. My itunes won't recognize my Ipod. Also I haven't gotten the BSOD so far.

    Are there other indicators I should check to see if all is clear??
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From normal boot mode, please run TDSSkiller and attach the log it creates to your next message.
     
  15. soph4

    soph4 Private E-2

    Oops, I have attached it now.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please now run, update first and then run a scan with Malwarebytes. Fix anything it finds and attach the log from Malwwarebytes.

    Then delete the copy of ComboFix.exe that you already have and download and save the below one to your Desktop:

    combofix.exe

    Now see if you can run ComboFix according to the instructions in the READ & RUN ME. Attach the log if it runs.

    Also if it runs, please explain what ( if any ) problems remain.
     
  17. soph4

    soph4 Private E-2

    OK I ran both Malwarebytes and Combofix last night and both found infections. The logs are attached.

    So far this morning I have had no redirects, which was the most obvious sign of infection.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it appears that ComboFix and Malwarebytes took care of the rest of your malware problems.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  19. soph4

    soph4 Private E-2

    Thank you, Thank you, Thank you!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds