Help removing trojans

Discussion in 'Malware Help (A Specialist Will Reply)' started by brian southwell, Jul 25, 2012.

  1. brian southwell

    brian southwell Private E-2

    I have tried to remove trojans that malwarebytes and the MS malware removal tool are detecting with no success. Can you help?
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

  3. brian southwell

    brian southwell Private E-2

    Thanks! I have been lurking here for years. This trojan pushed me to register!
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    Hi,

    This infection can be quite tricky but TDSSKiller seems to have a high success rate with it.

    http://img196.imageshack.us/img196/3557/tdsskiller.gif Rescan with TDSSKiller and allow it to Cure Rootkit.Boot.Pihar.c
    It will need to reboot your system, allow the reboot.

    Then attach a new scan when finished.
     
  5. brian southwell

    brian southwell Private E-2

    Looks like you got it!! Thanks!!

    Does the scan tell you if my whole system is clean?
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    http://img196.imageshack.us/img196/3557/tdsskiller.gif Re-scan with TDSSKiller except this time use the Change Parameters button and put a checkmark in TDLFS File System.
    Then rescan
    If TDSS File System appears, delete it!
    Then attach the latest TDSSKiller log. (How to attach)

    __

    We have a little more work to do but the bulk of your problems should be gone now.. I will post with further instructions later.
     
  7. brian southwell

    brian southwell Private E-2

    Here you go. Oh...I'm in Houston too.
     

    Attached Files:

  8. thisisu

    thisisu Malware Consultant

    Cool. This weather is something else isn't it ? :D
    Actually the rest of your logs look fine.
    Remaining steps before I give you a clean bill.

    http://img850.imageshack.us/img850/4746/programsandfeatureswin7.gif From Programs and Features (via Control Panel), please uninstall the below:
    • Java(TM) 6 Update 20 (outdated)

    __

    http://img850.imageshack.us/img850/4124/mbam.gif Run two more Quick Scans with Malwarebytes and attach both logs here.

    We want to make sure that C:\Windows\svchost.exe is no longer present as it just recreates itself when the rootkit is present.
     
  9. brian southwell

    brian southwell Private E-2

    Great weather. Like it used to be here. Rain and sun daily. Last summer almost killed me!
     

    Attached Files:

  10. thisisu

    thisisu Malware Consultant

    Definitely :)

    __

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     
  11. brian southwell

    brian southwell Private E-2

    Thanks very much for your help.:)
     
  12. thisisu

    thisisu Malware Consultant

    You're welcome :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds