Multiple Trojan Trouble

Discussion in 'Malware Help (A Specialist Will Reply)' started by cressy, Dec 16, 2009.

  1. cressy

    cressy Private E-2

    Hi,

    I was searching google images for visual aids, for a class I teach. Just random stuff, and I was culling a few jpegs from some blogs, when I got a "there is a virus" type alert from Avast Antivirus.

    I got a blue screen on resetting, restored to a previous state, and then started your Windows XP Cleaning Procedure.

    I ran everything apart from COMBOFIX, because I got the "ComboFix is not available for download until an issue with the program has been resolved" message.

    Also, when running MGtools it got past checking for .com files, got system resore info, got past zipping hijackthis.log and then paused at:

    updating: hijackthis.log (188 bytes security) (deflated 70%)

    I let it sit there for about 40 mins, but it didn't seem to be doing anything (I'm half expecting to be told I'm wrong here!). So I forced it to close and started this thread.


    I've attached my logs, and I'd like to thank whoever takes the time to read though my post.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We are going to try the beta version of ComboFix which is named KittyFix.exe

    Download KittyFix from http://download.bleepingcomputer.com/sUBs/Beta/KittyFix.exe
    and save it to your Desktop but do not run it.

    Note: This is a beta version of combofix and might be unstable but tests done so far
    have proved it works well

    Note: It is important that it is saved directly to your desktop and run


    from the desktop and not any other folder on your computer.
    • Now Exit/Close/Disable all anti virus and anti malware programs so they do not interfere with the running of
      ComboFix.
    • Close any open browsers and any other programs you might have running.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your
      Desktop) as KittyFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the KittyFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of KittyFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:
    Do not mouseclick combofix's window while it is running. That may cause
    it to stall.


    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp
    C:\Documents and Settings\Adrian1\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe
    file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still
    disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. cressy

    cressy Private E-2

    Thanks for taking the time to look at my problem.

    Kittyfix ran, but after it had completed the scans, when it rebooted and said it was producing a logfile, it hung for about 20 mins, so i ended the program. It didn't produce a combofix.txt file in my C: drive.

    I cleared out my temp folders, but I got a "cannot delete It is being used by another person or program" message for:

    Perflib_perfdats_7bc.dat and 710.dat
    and etilqs_uxoCjQ6433JGm4OiRxA2

    However, these are both files with todays date, so maybe thats ok?

    MGTools ran fine, and I have attached the log.

    Everything on my laptop seems to be working fine - but I'll hold off from doing any online shopping or banking till you give me the all clear!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\kittyfix" /uninstall
        • Notes: The space between the kittyfix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  5. cressy

    cressy Private E-2

    Brilliant!

    Thanks for helping out, I'll be sure to take more care in the future, keeping everything up to date.
     
  6. cressy

    cressy Private E-2

    Maybe problem?

    firefox is working fine, but IE and google chrome, both say "This web page is not avaliable"
    problems with my hosts file?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Make sure that they have not been changed to try and use a proxy server when you may not be using one. In IE, click Tools, Internet Options, Connections, LAN Settings. Not sure how to do this with Chrome since I don't use because I did not like it.
     
  8. cressy

    cressy Private E-2

    Nice one - that fixed it. Thanks again, merry Xmas and Happy New Year!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Happy Holidays and surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds