I believe I have the Black Internet trojan...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Paula320, Jun 29, 2010.

  1. Paula320

    Paula320 Private E-2

    I've read some posts on here about it and I'm pretty sure that's what is going on. I have Windows XP, AVG9, Malwarebytes, and SuperAntiSpyware which all have been unsuccessful in removing it. I've been dealing with it for about a month now. It started out with my sound just quitting one day in the middle of a game. Someone told me to reinstall my sound driver and update Directx so I downloaded my sound driver from Dell and the most up to date file of Directx from Microsoft. That fixed my sound (but it has happened a few more times and just had to reinstall the driver each time. Not sure what that's about but it's the least of my worries right now.) After that, Internet Explorer started popping up sporadically with various ads. I don't even use IE so that was really weird. I went to my task manager and saw iexplorer.exe running and killed it but it just kept coming back. So I realized something was going on. I ran AVG and it found these:

    "C:\System Volume Information\Microsoft\smss.exe";"Trojan horse Downloader.Generic9.CAXD";"Object is inaccessible."

    "C:\System Volume Information\Microsoft\services.exe";"Trojan horse Downloader.Generic9.CAXD";"Object is inaccessible."

    It wouldn't remove them and someone told me to run Trend Micro Housecall which did remove them until I rebooted then they just came back. Later on I found out how to make the System Volume Information file accessible and AVG Resident Shield is now able to move them to the vault and everything is fine until I restart my computer. Then they are back again.

    I've been talking to someone on the AVG forum and have run several scans and the last thing they asked me to do was to remove this key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{81ACBB45-06B6-AC1D-98EF-D6ECE7754907}

    It wouldn't let me delete it. I changed the permissions on it, I tried (under their supervision) to use Avenger with no success, and tried using the registry editor on the AVG rescue disk but the key will not delete.

    I found another person on this site that had this exact issue so I thought you might could help me with it. I've run the scans that are instructed in the Read Me First thread and will attach them. Please help me get rid of this. Thank you.

    Paula
     

    Attached Files:

  2. Paula320

    Paula320 Private E-2

    One more log....
     

    Attached Files:

  3. Paula320

    Paula320 Private E-2

    I'm reposting my MGlogs because I had moved it to the desktop to be easy to find but then I saw it needs to be in C.

    Well, it won't let me upload it again. I ran it from C, just moved the log to be easier to find. Let me know if I need to do something different.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Your infection is in your Master Boot Record (MBR). We need to see the below log before creating a fix.
    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe
    NOTE: The Command Prompt window text can be copied to the clip board by right clicking on the top bar of the window and using the Edit commands to Mark, Copy, and Paste.
     
  5. Paula320

    Paula320 Private E-2

    This is what I got from Bootkit remover:

    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    MD5: f3d9c702b9fb7144df9e0a91ffad275b

    Size Device Name MBR Status
    --------------------------------------------
    74 GB \\.\PhysicalDrive0 Unknown boot code

    Unknown boot code has been found on some of your physical disks.
    To inspect the boot code manually, dump the master boot sector:
    remover.exe dump <device_name> [output_file]
    To disinfect the master boot sector, use the following command:
    remover.exe fix <device_name>


    Press any key to quit...
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.


    Now - please do the following:
    • Click Start, Run then copy and paste the below into the Run box and click OK.
    "%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0
    • Now reboot your PC and after reboot continue with the below instructions.
    • Disable System Restore on all drives.
    • Look for the below folder and if if it sill exists, delete it.
      • C:\System Volume Information\Microsoft
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

      Then attach the below logs:
      • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Paula320

    Paula320 Private E-2

    It seems to have worked. Trend Micro Housecall and AVG9 both scanned clean and iexplorer.exe did not start back up. Here is the log you asked for. Thank you for your help.

    I wish I knew how I got this. I keep my AVG up to date and scan my computer often. I don't go to questionable sites. It happened right after I downloaded a sound driver from Dell and Directx from Microsoft so I assume it came from one of those places.

    Paula
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good but we have a little more to do.

    Not likely but not impossible. Based on some other info in your logs, you have had other infections since April. They may have been a precursor to this infection. In addition, you have at least one system file ( rasacd.sys ) that was replace by a fake at some point. Looks like you may have been playing with this since I also see an incorrect copy in C:\temp

    Let's get the bad system file fixed. Please download and save the below (click the blue link ) to your Desktop ( you must save it to your Desktop since my fix depends on it being there).

    rasacd


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Paula\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


    NOTE: You need to stop using MSconfig to control startups. See step 4 of the READ & RUN ME for explanation.
     
  9. Paula320

    Paula320 Private E-2

    I thought the MSConfig startup was just for controlling what started up. Thanks for clearing that up. I'll have it start normal from now on.

    Here are the logs you asked for.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Or use a real startup manager like one of the ones mentioned. ;) MSconfig was designed to be a temporary debugging tool.


    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. Paula320

    Paula320 Private E-2

    I've gone through all the steps you told me to do. I now have my computer starting in normal startup mode and have used the suggestions in the "Read me" section for disabling programs I don't want to run. I'll now have to do this for the three other computers in my house. lol

    I appreciate all your help very, very much! Like I said, it's been a month that I've dealt with this and believe me, a stressful month! It had already been suggested to me that I was going to have to reformat Windows and I did not want to do that! Thank you!

    Paula
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!

    And if you have malware problems with other computers that you need help with then each one should have their own thread. ;) Be sure to indicate that they are other PCs so that no one thinks it is this same PC again or that they do not think they are duplicate threads.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds