Help Trojan Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by scamp1, Jan 24, 2007.

  1. scamp1

    scamp1 Private E-2

    Hello, I am new to the forum and to this site. I have been hit pretty hard by a Trojan Dropper Virus. I was wondering if I am posting in the right place, I will post my problem and maybe we can go from there. thanks

    I followed your tutorial the best I could. I have downloaded, installed, and ran the following:

    1. counterspy (in safe mode with all the updates)
    2. Spybot search and destroy (in safe mode with all the updates)
    3. Ccleaner (in safe mode with all the updates)
    4. Both the Bitdefender and Panda scan online scans

    I could not get the Getrunkey or the Shownew tools to download.

    I have logs files from - hijackthis, bitdefender, ccleaner, panda scan

    I will post my hijack log below:
     

    Attached Files:

    • Hjt.txt
      File size:
      13.7 KB
      Views:
      1
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    You'll need to attach! all the logs requesed as per the guide ( inline logs will get caught by the spam filter as you noticed as your thread did not appear )


    One reason you may not be able to download ShowNew and GetRunKeys is that you need to tick the "remember me" box on logging into the forum.
     
  3. scamp1

    scamp1 Private E-2

    hhhelp VIRUS

    I followed your tutorial...but can not post

    These are my log files from ccleaner, bitdefender , and panda
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: hhhelp VIRUS

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. scamp1

    scamp1 Private E-2

    trojan help

    I did your tutorial to the letter...I am attaching the following logs

    bdscan, ccleaner, counterspy, pandactivescan, newfiles.txt, and runkeys.txt


    I have pasted in my highjack log below

    Edit: and I have removed it and attached in a 2nd post as mentioned in the guide
     

    Attached Files:

    Last edited by a moderator: Jan 25, 2007
  6. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    attached HJT log

    However you will have to complete Hijackthis again as its not installed in the location as specified in the guide, this is exactly were we mention not to install it C:\Documents and Settings\gmayhugh\Desktop\highjack this\highjack this\analyse.exe
     
    Last edited: Jul 22, 2007
  7. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    attached HJT log and merged your new thread into this as its best and good policy to keep all posts in the same thread for continuity.

    However you will have to complete Hijackthis again as its not installed in the location as specified in the guide, this is exactly were we mention not to install it C:\Documents and Settings\gmayhugh\Desktop\highjack this\highjack this\analyse.exe
     
  8. scamp1

    scamp1 Private E-2

    Have I given you enough information? If there is anything else you need from me please just post the request...sorry about having the highjack file in the post...my mistake...I am at work and will check back soon to see if you can help me....

    again many thanks
     
  9. scamp1

    scamp1 Private E-2

    NEW highjack log

    Sorry about installing that in the wrong place...I reinstalled it and generated a new log file...hope this helps

    thanks
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still having problems?

    Did you install Bitdefender and Panda ActiveScan (rather than just doing the online scan)?

    If so, you need to uninstall them! Having more than one anti-virus installed will give you problems.
     
  11. scamp1

    scamp1 Private E-2

    I did the on line scan only for both panda, and bitdefender - I am still having problems with my system - did you get a chance to look at my files:

    logs for:
    bitdefender
    ccleaner
    newfile
    runkeys
    NEWhighjackthis


    I hope you can help me I am at my witts end - oh one more problem, and maybe some advice - I had the free version of AVG when I got this virus, so I uninstalled it and installed the bitdefender trial - do you have any idea on how to uninstall it - it keeps giving me this message.

    "this action is only valid for programs that are currently installed"

    I wouls like to uninstall bitdefender and maybe go with norton

    who has the best virus protection software, in your opinion.

    thanks for all your help
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't think it is the AV that is so important (though I don't recommend paid for software), as much as the surfing hadits:
    How to Protect Yourself.

    You can re-run HJT and delete the following items:
    click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    O8 - Extra context menu item: RapidShare-Download - res://C:\Documents and Settings\gmayhugh\Desktop\RapidShare - the way YOU like it!\more-rapid.exe/RsMenExt.html
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing) G
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing) G
    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe

    After clicking Fix, exit HJT.

    Run CCleaner as I am still seeing things in your temp folder.

    Attach new logs for:
    GetRun
    ShowNet
    HJT

    And PLEASE tell me exactly what "issues" you are refering to....
     
  13. scamp1

    scamp1 Private E-2

    I understand the whole idea behind "bad surfing habits". I go places that I should not go and put myself at risk to often.

    My system seems to be running alot better, thanks for all your help - I just wanted to make sure it was real clean

    I have attached my new getrun - shownet - hjt logs

    again thanks for all your help, you saved me a format
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Again run HJT and have it fix the below items:


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.yahoo.com

    (If you don't know what this is remove it:)
    O8 - Extra context menu item: RapidShare-Download - res://C:\Documents and Settings\gmayhugh\Desktop\RapidShare - the way YOU like it!\more-rapid.exe/RsMenExt.html


    If this is on your desktop, remove it.
    Do a search for "more-rapid.exe" and delete it if found.

    Otherwise you look pretty clean.

    How to Protect Yourself

    Let me know if you have further problems.

    And don't forget to toggle system restore....trun it off, restart the computer and then turn it back on.
     
  15. scamp1

    scamp1 Private E-2

    I ran the HJT....and got rid of the R1 stuff....have no idea what the rapidshare thing is...but HJT will not delete it?......did a search and could not find it, I used window search tool - and also tried to follow the string - no luck, any advice

    I will attach my latest log -
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only other things I am seeing are these:

    If you don't know what they are, delete them.
    C:\Documents and Settings\gmayhugh\Desktop\NIS071020.exe
    C:\Documents and Settings\gmayhugh\Desktop\0580
    C:\Documents and Settings\gmayhugh\Desktop\05-1150
    C:\Documents and Settings\gmayhugh\Desktop\exterm-setup-0004.exe
    C:\WINDOWS\smproflt.dll

    I would also suggest that you uninstall this:
    ROR POP CD CRACK

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  17. scamp1

    scamp1 Private E-2

    thanks so much for all your help...I believe I am clean....whewww....again thanks, and keep up the great work
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your welcome.....safe surfing!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds