Nasty little trojan! (started as serauth1.dll etc.)

Discussion in 'Malware Help (A Specialist Will Reply)' started by OyVey, Mar 20, 2009.

  1. OyVey

    OyVey Private E-2

    Hi. Well, it's one of those days...... My laptop has been bitten by a nasty little trojan and I am having difficulty removing it.

    So it's like, I downloaded some proggy, and when I launched it, it shut down my Avast and re-started the PC. After that....... (deep breath):

    - Avast and Sygate are disabled (I can see all Avast application have today's date)
    - Wireless connection is disabled (lucky the LAN works!).
    - When I try to launch SUPERAntiSpyware I get the message "Not a valid Win32 application".
    - CCCleaner will not run (no message)
    - Combofix will not run ("Not a valid Win32 application")
    - Spybot will not run (no message)

    Only Malwarebytes will run......

    Now, the first time I ran it, it found two files:
    - Serauth1.dll
    - Serauth2.dll
    I removed both and they seem not to have returned.

    Second time I ran it, it found 12 (!) files (sorry I did not write them down), some Trojan Agent, some Spammer, etc. I deleted them and then.....

    After rebooting, and scanning using Malwarebytes again, I found a registry key for mule_st_key - deleted that and rebooted.....

    By the way, I updated the Malwarebytes definitions, and it worked the first time but on subsequent updates it says "not connected to net".... seems it is blocked.

    Also, I tried to run Kapresky, and it did start the process but after downloading the program and some of the database it stopped working and again says, "not connected"

    Oh, also by the way, system restore is off on my system....

    OK, back to the Malwarebytes scan.....

    Ahhh!!!! - 12 entries this time....
    I have attached the log file.....

    What now???

    Thanks
     

    Attached Files:

  2. OyVey

    OyVey Private E-2

    Attached MBAM log after another clean/reboot....
     

    Attached Files:

  3. OyVey

    OyVey Private E-2

    All well that ends well - thanks to MBAM!!!

    OK, so I was able to solve this myself..... through repeated runs of MBAM as well as manually cleaning out the registry and files where the trojan was hiding.

    Now things are back to normal, and the ONLY one that worked was MBAM!! Thank you!!

    By the way, like so many trojans, it also disabled my wireless. This is what you have to do to get it back:

    However, I did find such Protocol Service in the regedit, and I found out it was disabled (it was set to 4). So, in sum, I recommend you to go to
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio
    and check that the "Start" Value is set to 1, 2 or 3 (I set it to 1).

    And this solved my problem, after a System Restart the Wireless Zero Config Service can be readily started.


    (Original link)

    http://www.techsupportforum.com/net...4273-solved-error-1068-when-starting-wzc.html
     
  4. OyVey

    OyVey Private E-2

    Return of the Bagle!! Help!

    OK, maybe I spoke too soon..... Earlier today I posted this:
    http://forums.majorgeeks.com/showthread.php?t=185316

    I did manage to remove everything (or so I thought) and MBAM did not find anything. I completely un-installed Sygate, Spybot and SuperAntiSpyware and then re-installed them. No issues the entire day.

    But just now.... I saw my MSN Live was offline so I launched it (from STAR/Programs) and.... boom! Avast was disabled, just as before, and I thought to myself....

    (Unlike before, the system did not reboot - maybe a good sign that I acted quickly)

    So - *quickly* I disabled the wireless card and ran MBAM. It did detect Bagle and removed it, not to be seen on subsequent scan. My Sygate etc. are still showing "Not a valid Win32 application" and I guess I have to re-install them again.

    Another MBAM scan came up clean.

    My questions are:

    1. Apparently Bagle was hiding as MSN, why did the full system MBAM scan I did not detect it?

    2. Even now though a MBAM scan reveals nothing, how do I make absolutely sure it is gone for good?

    Thanks!
     
  5. OyVey

    OyVey Private E-2

    Re: Return of the Bagle!! Help!

    OK, it's confirmed, even after all is "removed", clicking on Windows Live Messenger activates Bagle.

    Fortunately I know where it drops its files and can kill the process and delete the files.

    BUT

    I can't make out which program is run by clicking on Windows Live Messenger (since they have disabled the "Find Target" button).

    Any ideas?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These were not your problem and there are other files that came along with these on the same date which are also not problems. Many people on the internet have been removing this files simply because no one knows exactly what they are but I have never seen them be a problem. The below files usually come at the same time
    You problem and the reason your wireless connection stopped working was the Rootkit.Bagle infection noted in your MBAM log. You could still hae additional malware related to this. It is recommended that you follow the below cleaning procedure to be sure. And by the way we have a procedure to fix the wireless interfaces that we use after fixing bagle infections. See: Fixing Wireless Zero Config Service



    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:



    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
    Last edited: Mar 23, 2009
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just noticed you started another thread on 3/20 confirming my suspicions that you still may have Bagle problems. Please remain in one thread.

    I merged your other two posts from the new thread back here. They are msgs #'s 4 & 5.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds