Need help removing Trojan FraudAV.SJhorwPa

Discussion in 'Malware Help (A Specialist Will Reply)' started by FerreroNatchos, Jan 22, 2013.

  1. FerreroNatchos

    FerreroNatchos Private E-2

    Hello,
    I have been following the Majorgeeks protection guidelines for years and everything works well. But now this thing got through: "FraudAV.SJhorwPa".

    This trojan is only detected by Spybot and even tends to disappear from the source file where it is indicated to be, but where Spybot still tells me it resides.

    Please help me declare war onto this enemy. :)

    Thank you.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. FerreroNatchos

    FerreroNatchos Private E-2

    So, should I install and run RogueKiller, etc.? (I have Windows Vista.)
    Or am I reading too far?
     
  4. FerreroNatchos

    FerreroNatchos Private E-2

    Well, here are the logs anways.
     
  5. FerreroNatchos

    FerreroNatchos Private E-2

    Take 2.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the log from Spybot so I can see what it is complaining about.
     
  7. FerreroNatchos

    FerreroNatchos Private E-2

    Here it is.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Unfortunately, that doesn't show what file is infected.
     
  9. FerreroNatchos

    FerreroNatchos Private E-2

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the logs from running:
    RogueKiller
    Hitman
     
  11. FerreroNatchos

    FerreroNatchos Private E-2

    They were in the "Logs" zip file.
    Here.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That didn't do it and it's not showing up in your logs.

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
  13. FerreroNatchos

    FerreroNatchos Private E-2

    Here is what came out of it.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That didn't find anything. Let me consult with my colleagues.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Click on the following link and use the below steps to scan a file: Virustotal

    Upload C:\Cleanup.exe

    Tell me the results.
     
  16. FerreroNatchos

    FerreroNatchos Private E-2

    First it told me that the file had already been analyzed on the 21st (Monday). I can't say how, so I clicked "reanalyze".

    I'll list the results in a second post.

    Heads-up: I realized there were some mistakes on my part in the sequences. After running Spybot, which would detect the trojan, I didn't always re-deactivate Antivir after reboots of the system, for example. This had the effect that Antivir would jump onto the Trojan and quarantine it by moving FraudAV.SJhorwPa elsewhere, I don't know where to. Since I know where the Trojan is supposed to be, I kept an eye on it directly, but because of the constant re-quarantining, FraudAV.SJhorwPa isn't always where it's supposed to be, making it harder for us to eliminate it, and for your suggested software to detect it. Right now, FraudAV.SJhorwPa is moved soemwhere and I can't find it, but Spybot still detects it (but won't tell me where it is either).
     
  17. FerreroNatchos

    FerreroNatchos Private E-2

    https://www.virustotal.com/file/1ae97262a5b5e5441cfd323d417bbf1ffc098b3f89511dede3acae0a9674dc09/analysis/1359145414/

    SHA256: 1ae97262a5b5e5441cfd323d417bbf1ffc098b3f89511dede3acae0a9674dc09
    SHA1: 619e67d565bb4e5ce9557aff4e0a3bdf8d11b74d
    MD5: d5816bddd4382975c1693cce68547fcc
    File size: 18.8 KB ( 19286 bytes )
    File name: cleanup.exe
    File type: Win32 EXE
    Tags: peexe mz
    Detection ratio: 14 / 44
    Analysis date: 2013-01-25 20:23:34 UTC ( 12 minutes ago )
    0
    0
    Less details

    Analysis
    Comments
    Votes
    Additional information

    Antivirus Result Update
    Agnitum RiskTool.Avenger!4K/L0L7NudI 20130125
    AntiVir - 20130125
    Antiy-AVL - 20130125
    Avast - 20130125
    AVG - 20130125
    BitDefender - 20130125
    ByteHero - 20130123
    CAT-QuickHeal Trojan.Agent.WD.cw6 20130125
    ClamAV - 20130125
    Commtouch W32/Zapchast.M 20130125
    Comodo - 20130125
    DrWeb - 20130125
    Emsisoft - 20130124
    eSafe Win32.Banker 20130120
    ESET-NOD32 - 20130125
    F-Prot W32/Zapchast.M 20130125
    F-Secure - 20130125
    Fortinet - 20130125
    GData - 20130125
    Ikarus - 20130125
    Jiangmin Trojan/Zapchast.gd 20121221
    K7AntiVirus Riskware 20130125
    Kaspersky - 20130125
    Kingsoft Win32.Troj.Zapchast.uy.(kcloud) 20130121
    Malwarebytes - 20130125
    McAfee-GW-Edition ZapChast.gen 20130125
    Microsoft - 20130125
    MicroWorld-eScan Win32.SuspectCrc (ES) 20130125
    NANO-Antivirus - 20130125
    Norman Zapchast.CTP 20130125
    nProtect Trojan/W32.Zapchast.19286 20130125
    Panda - 20130125
    PCTools - 20130125
    Rising - 20130125
    Sophos - 20130125
    SUPERAntiSpyware - 20130125
    Symantec - 20130125
    TheHacker Trojan/Zapchast.uy 20130124
    TotalDefense Win32/Crykee.A 20130124
    TrendMicro - 20130125
    TrendMicro-HouseCall - 20130125
    VBA32 - 20130125
    VIPRE - 20130125
    ViRobot - 20130125
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since we can't find it, there is a good chance Spybot is detecting it in a quarantine folder.
     
  19. FerreroNatchos

    FerreroNatchos Private E-2

    So what now?
    Awaiting orders.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issues are you having?
     
  21. FerreroNatchos

    FerreroNatchos Private E-2

    Oh, btw, more detail:
    When I tell Spybot to "fix it", Spybot gives me an error saying it "can't open the file", then I guess making it show that something is wrong, Antivir swoops in and quarantines the file altogether. BUT, Antivir is not able to detroy the Trojan. He is just cockblocking, right now.
     
  22. FerreroNatchos

    FerreroNatchos Private E-2

    Otherwise, I guess I can't say I noticed any issues.
    According to Spybot's forum (see link from a few days ago), the Trojan is supposed to make my computer download things in the background, which is bad. But, indeed, I can't say I noticed anything.

    So... stalemate for now, I'll wait for a patch from Spybot, I guess.

    Thank you for the help, TimW.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you attach the log from Avira?
     
  24. FerreroNatchos

    FerreroNatchos Private E-2

    Oh. Here you go.
     

    Attached Files:

  25. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, FerreroNatchos

    Spybot - Search & Destroy\Recovery\ <--those are SpyBot Quarantined Files
    The SpyBot malware detection FraudAVSJhorwPa.zip was itself quarantined by Avira on 1-21-13

    To empty SpyBot's Quarantine
    Quarantine can be either launched via the Start Center or can also be found in SDTray’s program list.
    Just right click on the Spybot – Search & Destroy icon in your traybar beside the Windows clock and navigate to “Basic Tools“ → “Quarantine“. Once “Quarantine“ has been started just hit the purge selected button.

    To empty Avira's Quarantine
    Start Antivir > Administration > Quarantine > Select the objects that you want to delete > Click on "Delete selected object(s) from quarantine".
     
  26. FerreroNatchos

    FerreroNatchos Private E-2

    I deleted the items in Antivir's quanrantine.
    But, I cannot find Spybot's "Start Center" and I do not have the SBTray icon (I try to have as few tray icons as possible.) Because of that, I canot find the quarantine area in Spybot. I went to their tutorials and forum; no clue.

    What next? I'll run Spybot again in the mean time.
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, run Spybot and see what it reports.
     
  28. FerreroNatchos

    FerreroNatchos Private E-2

    Still there.
     
  29. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The newfiles.txt log shows your SpyBot version is 1.5.2.20. If that is correct, it's outdated by several versions with 2.0.12.0 being the latest.

    You could use Revo Uninstaller to do a deep uninstall and remove all left-over folders & registry entries.

    *When deleting registry entries, you should only select each bold typed leftover item (those are SpyBot related) by left-clicking in the box next to it, then clicking the Delete radio button... then the Next button when prompted.

    Re-boot, then download and install Spybot-Search & Destroy 2.0.12.0 Final .

    Run a new scan with SpyBot and attach the log.
     
  30. FerreroNatchos

    FerreroNatchos Private E-2

    Huh. Apparently, clicking the "Update" button doesn't actually update the software that much. I have version 1.6.2.46, according to the "About". I will do as you said and come back later with the result.
     
  31. FerreroNatchos

    FerreroNatchos Private E-2

    Good news!
    It was as simple as that. I did two scans with the new Spybot 2 (now I understand what that "quarantine" and "Start center" things were) and on the first time, it detected the "cleanup.exe". I "fixed" it. 2nd scan, it wasn't there anymore.

    Huzzah!

    I think we're done! :)

    Thanks a whole lot! Nice work, guys!
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  33. FerreroNatchos

    FerreroNatchos Private E-2

  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds