I have two trojans!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jovi3, Mar 10, 2009.

  1. Jovi3

    Jovi3 Private E-2

    My NOD32 told me it got rid of these two trojans:Win32/Kryptic and Win32/Olmarik but it seems it did not do it quite right since IE and Firefox are not working. I have Safari and that's why I can ask for help, please!!!!!!!

    Sometime ago I got Combofix for another issue and I worked like a charm. Since I was kind of deperate this time I tried it again and it said it was an old version and never opened again.

    I tried all the solutions you suggest:
    Malvare Anti Malwarebutes it does not install, I rename it, start the installation and never finish...
    SUPERA says it has encountered a problem and need to close...
    The only program I was able to make it work was a DDS that produces a log similar to Hijackthis.
    Can you guys help me???
    Here is the log
     
  2. Jovi3

    Jovi3 Private E-2

    Sorry, trying to attach the log!!!
     

    Attached Files:

    • DDS.txt
      File size:
      9.2 KB
      Views:
      5
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. If you got that to run, I should think you will manage to get MGTools.exe to run. If not try renaming it to 123.com, and the same for combofix, rename to abc.com and try again.

    Ensure that you have the latest version of MGTools (refer to the Read and Run Me First link and download the most current version)

    Let me know how you get on.
    Thanks
    Kes13!
     
  4. Jovi3

    Jovi3 Private E-2

    Hi:

    Thanks for your answer. I was able to run MBAM, and it cleaned a lot. Then I was able to run HJ and Combofix ( I was told to remove it) After that I installed a Sunbelt personal firewall. Here are the logs. Am I ok or do I have to install GMER?

    Thanks!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could I please see the logs from running MBAM SAS and MGTools? To properly remove malware I really need the Mglogs.zip

    Thanks
    Kestrel13!
     
  6. Jovi3

    Jovi3 Private E-2

    Here is the MGlogs
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, that's great. Give me some time now to review the logs, and I'll get back to you with a set of instructions as soon as possible. You have the logs frmo MBAM and SAS too? I would like to see those. (apologies if you're about to attach them)

    Thanks
    Kes
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SAS log found here:
    MBAM log found here:
     
  9. Jovi3

    Jovi3 Private E-2

    Here are the SAS and the MBAM logs.
    Thanks!
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    whilst I see you are logged in... could you attach the below for me?


    and the below MBAM log:

    Thanks
    Kes
     
  11. Jovi3

    Jovi3 Private E-2

    Here are the logs
     

    Attached Files:

  12. Jovi3

    Jovi3 Private E-2

    Hi:

    Did you get a chance to look into my logs? Let me know!

    Thanks!
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. I am currently still working under supervision, so if you bear with me a little longer I will get back to you :)

    Thanks for understanding
    Kestrel13!
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation.

    2) Now we need to use ComboFix to remove a bad service.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    Drivers::
    srosa
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    3) Please tell me what the below is and what is it doing in this folder?

    • c:\program files\Bichono.exe


    4) FYI:

    The ComboFix folder should not be renamed since ComboFix and even we would have suspicions about it. Also when you uninstall CF, the folder would not be removed since it does not look for that folder name.

    5) Now Run Ccleaner!

    6) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    7) Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  15. Jovi3

    Jovi3 Private E-2

    Hi:
    I cleaned my desktop although I have some programs to remove. I will only leave icons and folders, is that ok?
    I run ComboFix, CCleaner and MGtools and here are the logs.
    The c:\program files\Bichono.exe is actually HJT renamed.
    Things are running ok although the Sunbelt personal firewall was disabled by CF and I can not make it work. I will try the troubleshooting.
     

    Attached Files:

  16. Jovi3

    Jovi3 Private E-2

    So, am I clean?

    Let me know,

    thanks!
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please be patient with me, we have been extremely busy, and I am still working under supervision as I explained. I'll get back to you with "all clean" if you indeed are, ASAP ;)
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    and finally...

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  19. Jovi3

    Jovi3 Private E-2

    The registry addition worked succesfully. Combofix was removed and I will purchase one of the SAS or MBAM, which 'd you recommend?
    Everything seems to be running fine, is my PC safe, for example, to buy anything using a credit card or once the security is compromised is not safe anymore?
    Thanks for all your help!
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes you are safe. :)

    Purchase either MBAM or SAS...both are as good as each other.

    Take Care
    Kes
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds