Internet Problems: Trojan Virus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Twistid, Feb 4, 2009.

  1. Twistid

    Twistid Corporal

    I have been having fluctuations in my internet at random times. My dad called up a computer networking technician they use at his work and he said that it could be a Trojan. I have been dealing with this fluctuating internet issue for maybe a month or so.

    I followed the READ AND RUN ME FIRST Malware Removal guide, but the internet has fluctuated at least once so far (after it found a trojan in the process).

    I've tried replacing the Ethernet Card with another one and it still continues. Also have replaced my modem and Ethernet wire and it still persists.

    I've also been having BSODs occur at completely random moments and at first they only seemed to occur when i wasn't at the computer, but that no longer seems to matter, because the last one that happened was as i was using the computer. More detailed information about the BSOD situation can be found at my other post in the drivers forum: http://forums.majorgeeks.com/showthread.php?t=178781 . Also, I am running an XP machine.

    I also just checked if System Restore was enabled and for some reason it was. Not sure if that's what maybe ComboFix did or one of the other scanners or for some reason it was enabled again, because i believe I had it turned off previously. I have disabled it now.

    All logs are attached.
     

    Attached Files:

  2. Twistid

    Twistid Corporal

    Here's the remaining log file.
     

    Attached Files:

  3. Twistid

    Twistid Corporal

    Considering the fact that I may have not had System Restore disabled during the scans I Performed another Quick Scan with Malwarebytes partially because it is a quick scan but also because it was one of the ones that obviously found something. It found a Hijack.StartMenu infection again and I just now told it to remove it and it did. I restarted my computer, did another scan with Malwarebytes and it was not there again. I don't want to assume the problem(s) are fixed now of course so i still await any further instruction.

    Also thought I should mention the driver that the Debugging Tools for Windows mentioned for the BSOD memory dump said that it was probably caused by avgtdix.sys. I do have AVG Anti-Virus installed on my system and I have attempted to uninstall it and reinstall it, but the BSODs continued. The problem now appears to have been a virus so it seems that problem needs no answering anymore save for possible remaining infections if they have not already been fully removed.
     
  4. Twistid

    Twistid Corporal

    Problem just happened again about 5 minutes ago. Connection just dieing and coming back, dieing and coming back. This is really getting on my nerves at my computer. I'd appreciate any help, thank you.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean......the scans removed the malware. As you noticed, it is a good idea to use the tools on a regular basis, depending on your surfing habits.

    As to your internet issue.....two things to do:
    If you are using a router, disconnect and plug in directly to the modem.
    Call your isp and have them test the line.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  6. Twistid

    Twistid Corporal

    Thank you very much for the reply TimW =). I've followed all of the newest directions you have left for me to do in this post save for contacting my ISP or directly connecting to the modem.

    I have one thing I thought I should mention for those who may be having problems with Combofix and are running AVG Anti-Virus as I am.

    When I was attempting to use Combofix (both for the scanning part and also for the uninstallation part) I would get a message that said "An unhandled win32 exception occurred in Prep.com." and also a false positive showed up from AVG also when trying to start Combofix. What I did was I went to Control Panel -> Administrative Tools -> Services and double-click the AVG8 WatchDog service. Under the General tab change Startup type: from Automatic to Disable and under the Log On tab select whichever Hardware Profile you intend on using with Combofix or if you haven't created or changed the Hardware Profiles to just select Profile 1 and click the Disable button. Restart your computer and once it starts up right-click on the taskbar and select Task Manager click the Processes tab and right-click the
    avgrsx.exe process and click End process tree.

    This is what I had to do for me to be able to get Combofix running so I hope this helps. Of course after you have run Combofix you just go back into the Services item in the Control Panel and you reset the Startup type to Automatic and re-enable the Hardware Profile for AVG and restart the computer.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....numerous AV programs do not like ComboFIx and need to be disabled before running it.
     
  8. Twistid

    Twistid Corporal

    Well the virus has been removed, but for some reason i am still having BSoD issues :(. I just had another one today. Should I get help for that here or elsewhere in the forums?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, post in the software forum and make sure you tell them the exact error message when you get a BSOD.
     
  10. Twistid

    Twistid Corporal

    I just ran another quick scan with Malwarebytes and Hijack.StartMenu has shown up again :(.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have no idea what you are referring to....
     
  12. Twistid

    Twistid Corporal

    O i think it's a false alarm lol sorry. I recall in Spybot it not liking a certain system setting that I wanted set. This appears to be the same thing. It has a problem with this registry entry: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs. Which to me appears to be the setting for showing My Documents or not in the start menu. Since I don't ever use My Documents I have it disabled. Sorry for the mix up lol.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds