Downloader - AWX trojan is killing me

Discussion in 'Malware Help (A Specialist Will Reply)' started by insideout, Oct 12, 2006.

  1. insideout

    insideout Private E-2

    I was referred to you by the IT director at the company in which I work. My PC is getting slammed with Downoder-AWX trojan. Simptoms include uncontrolled popups in IE. I'm even getting popups when I'm not connected. I have cable internet, so I suppose that probably means I'm always connected :confused:

    I followed the steps in your instructions and now I'm to the step where it asks to attach the HJT log file. I hope you guys can help, and I totally appologize if I've not followed any of your procedures correctly. This is insanely confusing, so please go easy on me :)

    Thanks a million for your help!
     

    Attached Files:

  2. insideout

    insideout Private E-2

    Sorry I just saw that I missed some things. I'll post an update when I have all the logs.
     
  3. insideout

    insideout Private E-2

    Evidently, I fall under the category of "too stupid to own a computer" :rolleyes:

    I have spent all evening trying to follow the instructions.

    All in safe mode:
    I was able to run ccleaner - yeah!
    Cant find MS Windows Malicious software removal tool anywhere!
    Spybot S&D will not run without updates and it will NOT update - keeps timing out
    Windows Defender worked - probably because I already had it and run it every day.

    Reconnected Internet:
    Can't find anything that even remotely resembles bitdefender, or panda ?????

    I'm attaching the log files for getrunkey and shownew scans.

    If anyone can see their way past my complete stupidity, PLEASE HELP!

    Thanks,
    I/O
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to follow the directions in the READ ME to download and run it.


    Again follow the directions in the READ ME. These are not things on your PC. They are websites that you need to goto to run the online scanners. Run these two scans and save the logs as requested then attach them.

    Then run this Virtumonde aka Trojan Vundo Removal and attach the log from VundoFix as requested.


    Now goto Add/Remove programs and Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    Screensavers Installer

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    After doing all of the above attach new logs from ShowNew and HJT.
     
    Last edited: Oct 14, 2006
  5. insideout

    insideout Private E-2

    Like everything else with this computer, nothing makes sense. I KNOW I posted all of the following logs yesterday, after 8 hours of running scans. Anywho, here goes again. Hopefully they'll stick this time. Thanks in advance for any help you can give me. To recap what I did, I completely started over. Ran all the suggested programs in safe mode, re-connected cable internet, and ran bitdefender and Panda. Ran Virumonde Vundo removal, removed J2SE lines and screensaver installer from Add/Remove, and finally intalled Sun Java. I hope I got everything.
     

    Attached Files:

  6. insideout

    insideout Private E-2

    Here's the rest of the logs.

    Thank you again for any help. I sincerely appreciate it!!!


    PS, I also KNOW that I ran bitdefender, and saved bdscan to my c drive. It was there yesterday when I uploaded all the logs. Now I'm ready to re-upload, and it isn't there. I freakin give up man
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never renamed HijackThis.exe as requested in step 7 of the READ ME. This is very important as indicated in the READ ME. Without doing this, some new forms of malware will not show in your log!! Please rename it NOW. I will post a fix below and hopefully it will work anyway, but when you post the follow up HijackThis log I will request, you must have the HijackThis.exe file renamed!

    Start by downloading a tools we will need - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O2 - BHO: (no name) - {A64EEA9C-BED6-4D0E-BC3F-265B949D7C34} - C:\WINDOWS\system32\hid13n.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O9 - Extra button: (no name) - AutorunsDisabled - (no file)

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\vtstq.exe
    C:\WINDOWS\system32\hid13n.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now after reboot attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. insideout

    insideout Private E-2

    Ok, I followed your instructions, and everything seemed to work fine. I've rebooted, and I'll attach the new shownew and HJT logs. Just an FYI, I did rename HJT to analyse.exe. For some reason, the log still says HJT, but I am 100% positive that the executable file is named analyse.exe before I ran it.

    Again, I am eternally greatful for your help chaslang!!!!!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This time it is correct. Last time it was not! You can check that for yourself just by looking in the logs. Renaming the executable file has nothing to do with what the log file will be named.

    Did you remember to exit all browsers and also remember to click Fix checked in HijackThis? The lines I asked you to fix are still there. See for yourself. Please try again, but this time before running HJT make sure ALL browsers are closed and also let's disable Windows Defender first too:

    To Disable Windows Defender's realtime protection:

    Disable Windows Defender:
    • Open Windows Defender
    • Click Tools
    • Click General Settings
    • Scroll down to Real Time Protection Options
    • Uncheck Turn on Real Time Protection (recommended)
    • Close Windows Defender
    Once your log is clean you can re-enable Windows Defender Real Time Protection.

    The repeat the previous steps with HijackThis. Then reboot and attach a new HJT log.

    Also make sure you indicate how your PC is running!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds