Infected with Trojan Horse SHeur2.AEFY

Discussion in 'Malware Help (A Specialist Will Reply)' started by sjbryce, May 14, 2009.

  1. sjbryce

    sjbryce Private E-2

    Hello:

    First time using this forum so hopefully I have done everything correctly.

    I am running Windows XP Home Edition w/ SP3. I use AVG Free Edition Version 8.

    Recently AVG was reporting that the machine had become infected with numerous trojan horses and/or malware.

    I have therefore followed all of the instructions in the "Read & Run Me First", and have run my machine completely through the Windows XP Cleaning Procedure as described in this forum.

    Apparently now the only item that remains on my machine is the Trojan Horse SHeur2.AEFY (as reported by AVG). The machine seems to be operating normally, however I continually get periodic messages from AVG reporting that the Trojan Horse SHeur2.AEFY exists in the following path/file:

    C:\Program Files\pplive\pplives.exe

    I have attached the relevant log files generated during the cleaning procedure as directed. I would greatly appreciate any help that can be provided to rid my machine of this malware. Thank you in advance.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome. We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time.

    Kestrel13!
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Did you knowingly install the PPlive software?

    It was installed on 5th May this year... ring any bells?

    There is a file we would like to take a closer look at.

    So in order for us to do that could you please navigate to the below bold file:

    c:\windows\system32\localtest.exe

    Check to see if there is a signature and let us know the findings in your next reply. If this doesn't yield enough information we can try something else. Also let me know about the PPlive.

    Thanks
    Kes13!
     
  4. sjbryce

    sjbryce Private E-2

    Hi Kes13:

    Thanks for the reply. I should first give you some updated information since my original post.

    After my original post, I went ahead and flushed my system restore points, as I had not yet done this. Additionally, I went ahead and deleted the C:\Program Files\pplive\pplives.exe, as well as the folder itself. I then went completely through the system registry and deleted all entries related to PPlive. (To answer one of your questions, neither myself nor my other family members who use this machine recall installing the PPlive software on May 5, therefore it must have been inadvertantly installed.) The folder/file (or any registry entries) have not reappeared in my system.

    Since performing these actions, AVG has not detected the Trojan Horse SHeur2.AEFY and/or the PPlive file(s). However, AVG is still reporting that it is finding some residual malware. Below I have pasted the info reported by AVG from yesterday's (May 16, 2009) system scan:

    ***begin paste from AVG***
    File:
    "C:\Qoobox\Quarantine\C\WINDOWS\Temp\739371346.dll.vir"
    Infection:
    "Trojan horse PSW.Agent.AAGS"
    Result:
    "Moved to Virus Vault"


    File:
    "C:\WINDOWS\system32\avp.dll"
    Infection:
    "Trojan horse Downloader.Agent2.CWH"
    Result:
    "Moved to Virus Vault"
    ***end paste from AVG***

    With respect to your question about the c:\windows\system32\localtest.exe file, I am not positive that I know how to correctly check if there is a file signature. What I did was right-click on the filename, select "Properties", then clicked on the "Summary" tab. All of the fields in the Summary tab are empty.

    Thanks very much for your help so far.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    shouldn't really do this until we have finished the thread, as a "dirty" restore point is better than none at all.


    This is just what combofix has quarantined. Nothing to worry about.


    This component is part of Xilisoft Video Converter


    Let's rename the file and you can leave it a couple days and tell me if your machine experiences any instability.

    c:\windows\system32\localtest.exe.old

    Navigate again to the file > right click > rename it to what I have above in bold.
     
    Last edited: May 17, 2009
  6. sjbryce

    sjbryce Private E-2

    Hi Kes13!:

    Thanks for the reply. Sorry about the restore system points....I will not take any further actions other than the instructions you give me.

    I have renamed the file c:\windows\system32\localtest.exe
    to
    c:\windows\system32\localtest.exe.old

    FYI, today's AVG system scan was clean with no infections or warnings. I will provide an update on the health of my system in a couple of days.

    Thanks again for your assistance,
    sjbryce
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome! :) Yes do report back to us in a couple of days and then if all is well we can get onto giving you the final steps.
     
  8. sjbryce

    sjbryce Private E-2

    Posting an update. I have had clean daily scans by AVG with no threats or infections over the past 3 days. So all seems much better at this point (knock on wood??!!)

    Thanks,
    sjbryce
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK let's just use Windows Explorer to delete the below bold file that we re-named:

    c:\windows\system32\localtest.exe.old

    and finally... :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  10. sjbryce

    sjbryce Private E-2

    Hi Kes13!

    Thanks very much for your assistance. I will follow your instructions on the final steps.

    This is an excellent forum, and once again your help is greatly appreciated.

    Best Regards,
    sjbryce
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hey no problem! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds