Cant Remove Trojandownloader:o97m/donoff.f

Discussion in 'Malware Help (A Specialist Will Reply)' started by budzz, Aug 4, 2016.

  1. budzz

    budzz Private E-2

    Approx 1 week ago, Out of the blue I noticed avira displaying random popups saying it either found a suspicious file or suspicious pattern and it was removing it.
    It got to the stage whereby it was notifying me everytime I started up of this and it would scan the pc, and today it had 3 instances of the avira scanner running all at once.
    After a week and several scans avira, emsisoft antimalware, malware bytes, windows defender, superantispyware, eset online scanner just to name a few and following the malware removal guide Im now here asking for help on how to remove the above trojan.
    Please see attached logs of scans.
    PC is
    Windows 10 64 bit
    Mozilla Firefox 48.0
    Let me know what other info you may require.
    Thanks in advance
     

    Attached Files:

    Last edited: Aug 4, 2016
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware. Please attach a log from Avira so I can see what it is complaining about.
     
    budzz likes this.
  3. budzz

    budzz Private E-2

    I cant see how to get the log out of avira or windows defender, but heres one from emsisoft which shows what avira supposedly had quarantined. I've also attached an image of what avira shows on every start up usually 3 pop ups every time and the amount of suspicious patterns varies, also a picture of what windows defender finds (again I dont know how to get the log out of that)
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.

    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
    budzz likes this.
  5. budzz

    budzz Private E-2

    Logs as requested, Thank you
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)

    Now, do this and attach the log:
    eSet Online Scan.
     

    Attached Files:

    budzz likes this.
  7. budzz

    budzz Private E-2

    also done as asked thank you
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is windows defender still showing the infection? If so, are you deleting them>?
     
    budzz likes this.
  9. budzz

    budzz Private E-2

    If I disable avira real time protection, windows defender starts up and will eventually come up with the message as per the picture below. It doesn't give me any option to do anything.
    When I look in the history tab>quarantined items of defender, there is nothing there, but when I go into 'All detected items' there is the list of infections as per above 'windows defender' jpg and I remove all then; only for them to come back again next time I start the pc.
    At the moment with avira 'real time protection' enabled, I get 3 of the avira warning pictures as per above post and avira starts 3 separate scans and when they complete they all ask to reboot the pc to finish the cleaning, which I do to no avail.
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    A question, please: referring to your post #3
    What info do you find out when Avira's "Security Alert" pop-up appears and you click on the Details radio button?
     
    budzz likes this.
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
    budzz likes this.
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ComboFix cannot be run on Windows 10.

    At this time ComboFix can only run on the following Windows versions:

    • Windows XP (32-bit only)
    • Windows Vista (32-bit/64-bit)
    • Windows 7 (32-bit/64-bit)
    • Windows 8 (32-bit/64-bit)
     
    budzz likes this.
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download this file to your desktop

    Kaspersky Virus Removal Tool

    Run the program you have just downloaded to your desktop (it will be randomly named )

    First we will run a virus scan.
    • On the first tab select all elements down to Computer and then select start scan.
    • Once it has finished select report and post that.
     
    budzz likes this.
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I recommend that before running Kaspersky all the other anti-virus/anti-malware programs be uninstalled first and then a reboot. The below should be uninstalled and any leftover folders should be deleted to get rid of quarantines.

    Avira Antivirus
    Avira Launcher
    ClamWin
    Emsisoft Anti-Malware
    SUPERAntiSpyware

    Delete the below folders:
    C:\Program Files (x86)\Avira
    C:\ProgramData\Avira
    C:\Program Files (x86)\ClamWin
    C:\Program Files (x86)\Emsisoft Anti-Malware

    I suggest running FRST again to make sure they are all uninstalled properly and also use FRST to delete any leftovers.

    Then I suggest disabling System Protection in Windows 10.
    Then boot in Safe Mode and try running Kaspersky.
     
    budzz and TimW like this.
  15. budzz

    budzz Private E-2

    When I clicked the details tab, as always with avira. it just made the pop up disappear and then the luke filewalker would appear and start scanning the pc as pictured. I've attached a log of the last scan it did tonight
     

    Attached Files:

  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    https://www.google.com/search?q=3E8...5326A&ie=utf-8&oe=utf-8#q=+PUA/Softpulse.oany

    Let's see if AdwCleaner finds it:
    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.
     
    budzz likes this.
  17. budzz

    budzz Private E-2

    Uninstalled all AV and downloaded and ran Kaspersky Virus Removal Tool, and it sounded like a different version as it didn't give me the option to select all elements or select a report once the scan was finished.
    It did show 'No threats found' after I scanned twice.
    Will now try the AdwCleaner above.
     
  18. budzz

    budzz Private E-2

    Log as requested
     

    Attached Files:

  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Ok - quite a few things the tool didn't like!

    Using AdwCleaner.exe previously downloaded:
    • Double click on AdwCleaner.exe to run the tool. (Vista, Win7/8 users should right-click and "Run As Administrator")
    • Click on the Scan button.
    • When the scan has completed, click on the Clean button.
    • Press OK when asked to close all programs and follow the on-screen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Upload this log to your next reply.
     
    budzz likes this.
  20. budzz

    budzz Private E-2

    Log as requested, thank you
     

    Attached Files:

  21. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome

    Please now run a scan with Windows Defender and let us know of any malware detections.
     
    budzz likes this.
  22. budzz

    budzz Private E-2

    Nothing there in defender. and it hasn't found anything whilst in real time mode either over the last few days
     

    Attached Files:

  23. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Good!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
    budzz likes this.
  24. budzz

    budzz Private E-2

    Just a final question as I go through the final steps above, is it recommended to reinstall avira antivirus or will windows defender do?
    Or perhaps you can recommend another better free antivirus,
    You opinion is greatly appreciated again. A VERY BIG THANK YOU to ALL involved, I really appreciate all the great help and expertise you have given me.:D
     
    dr.moriarty likes this.
  25. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Now that question will get you quite a few opinions in our Software Forum. Since I haven't upgraded to Win 10 (and I use Comodo Internet Security by the way), I'll give you this custom Google search and let you decide.
    https://www.google.com/search?q=sit...s=cdr:1,cd_min:7/1/2015,cd_max:8/13/2016&tbm=

    *On behalf of ALL of the members of the Malware Removal Team, you are most welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds