Malware, annoying Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by rexer, Nov 19, 2010.

  1. rexer

    rexer Private E-2

    Hi. I've been working on a computer with an annoying trojan called AV8,
    at least I'm led to believe that's what it is. Following the steps on the
    malware removal page, this booger keeps returning like a ghost. Just
    when I think it's gone, it appears.
    Undaunted, I proceeded to re-run some of the scans mixing in a defrag
    program. It seems to sturr a virus out of the nest enough to get it's head
    chopped off. After a third time, everything seems O.K.
    Nevertheless, it's beyond me if it's still there. My final assurance is to let
    you guys expertly look at my logs.
    Avast! found it on a scan but said it couldn't remove it from the file. In
    the scans of other malware/spyware programs, I never seen AV8 in the
    logs. Just something else called, 'Hiloti' Malware Bytes found and a thing called 'Fake Bill' spybot listed. I'm wondering if they aren't part of AV8's
    compostion. Anyway, attached are the logs.
    I love your malware removal guide. When I get a problems with my
    computer I come to this site. I one time or another bought all the scans
    and tools I use recommended by you folks. It's good stuff. Thank's for
    being there!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It appears as though you did not allow MGTools to run to completion as only one log was produced. Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  3. rexer

    rexer Private E-2

    Hi. I think I got the whole log now. Let me get it over to you so
    you can examine the logs.

    Thanks,
    Rex
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just so we can hopefully at least make a start, try this:

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  5. rexer

    rexer Private E-2

    Hi, Kestrel13,
    Well, an error message did surface.
    "The program or feature "\??\C:|MGTools\locate.com" cannot start or run due to
    incompatibility with 64-bit versions of Windows. Please contact the software
    vendor to ask if a 64-bit Windows compatible version is available."
    I guess that ended that. Thanks, anyway. Help is always appreciated. Rexer
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Instead of trying to run ShowNew and GetRunKey, try running SN64 and GRK64 and tell us what happens.
     
  7. rexer

    rexer Private E-2

    Hi Chaslag,
    C:\MGtools>SN64 reads, 'SN64' is not recognized as an internal or external command,
    operable program or batch file.
    The same is for GRK64. I'm getting pretty use to seeing this with 32 programs on 64
    bit machines. The first time I tried to run a 32 progam on 64 Windows, I was really
    blown away. But I guess that's the way Windows and the PC world is going.
    I'm not current if they resolved those problems. Anything new? Thanks Much. rexer
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    GRK64 and SN64 are 64 bit versions of the programs. Do you see the GRK64.bat and SN64.bat files in the MGtools folder?
     
  9. rexer

    rexer Private E-2

    Hi, Chaslang,
    Checking the MGtools folder, I didn't see GRK62.bat nor SN64.bat.

    -rexer
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you either have a very outdated version of MGtools or when you originally ran MGtools.exe, it did not finish running properly. ( Also it is GRK64.bat that we are looking for ). Do you have viewing of file extensions enabled as requested in the READ & RUN ME.

    Do the below.

    Click Start, Run, and enter cmd and click OK. A command prompt window should open. Type the below in the command prompt window and hit enter ( there are spaces after the dir and before and after the > )

    dir C:\MGtools > C:\flist.txt

    Now attach the C:\flist.txt file.
     
  11. rexer

    rexer Private E-2

    Hi Chaslang,
    Nothing listed in the cmd window. However, I went into MGtools files in C:, to
    ShowNew.bat and found the same 64 incompatibilty message in it. Cannot
    start or run due to incompatibility with 64 bit versions of Windows. I figure when
    I went into MGlogs, to ShowNew.Bat, C:\Windows\system32\cmd.exe window pops
    up with a message, Running scan with ShowNew.Bat - (c) 07/01/2006. Another
    window pops up, Unsupported 16 Bit Application, says
    The program or feature "\??\C:\MGTools\ltime.exe cannot start or run due to
    incompatibility with 64 bit versions of Windows. Please contact the software vendor
    to ask if a 64-bit Windows compatible version is available. I figured my MGTools is an
    older version. Thanks, rexer
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing was supposed to. I asked you to attach the flist.txt file. That is where the info was sent.

    You are not supposed to run ShowNew.bat. It is for 32bit systems. SN64.bat is for 64bit systems.
     
  13. rexer

    rexer Private E-2

    Hi Chaslang,
    Here is the txt file. 64bit MGtools aren't listed. Will re-download and try again.
    Thanks, rexer
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! As I stated earlier that I thought you were using a very outdated version of MGtools which is why you were getting the error. Current versions ( for a very long time now ) have automatically detected x64 systems and run the correct files.
     
  15. rexer

    rexer Private E-2

    "GRK64 and SN64 are 64 bit versions of the programs. Do you see the GRK64.bat and SN64.bat files in the MGtools folder?"
    They are there now, as the DIR file will show. What would you like me to do next?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it runs properly when you download and use the current version of the program. ;)

    Step 2 of the READ & RUN ME which you appear to have skipped too. You have Norton 360 and Avast running. After uninstalling one, you will have to attach a new log from MGtools.
     
  17. rexer

    rexer Private E-2

    Good morning! Here is the log.
    Reread the README and did as you asked...AVAST has been uninstalled. Hopefully everything is all good now!
    Have a good one,
    Rexer
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    Java(TM) 6 Update 7

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

    After clicking Fix, exit HJT.


    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Windows\system32\xbl1j7.dll
    C:\Users\Victoria\AppData\Local\Axuzohek.dat
    C:\Users\Victoria\AppData\Local\Tdalebev.bin
    C:\ProgramData\Alwil Software
    C:\ProgramData\fKmLg02041                                               
    C:\$AVG8.VAULT$
    C:\Users\Victoria\AppData\Local\Temp\_avast5_
      
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  19. rexer

    rexer Private E-2

    Chaslang,
    Everything seems to be running normally. The PC is much happier now. I just don't want any traces left. I'm trying to be careful about the spyware stuff.
    On a seperate note, I was planning on purchasing a spyware protection software. It's the real-time protection stuff I was looking for. Do have a personal preference, such as Malwarebytes?
    Thanks,
    Rexer
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    Malwarebytes is well worth the investment.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds