Persistent Trojan Help Needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by dadofive, Dec 18, 2010.

  1. dadofive

    dadofive Private E-2

    This problem started 6 weeks ago or so. I would run the clean up process and everything would be cool for a week or so and then it would return. Only visiting extremely safe sites, fb, and mainstream politcal stuff. I get a win32 error, then it opens a new browser window and redirects, etc. Here are my log files. Thank you.
     

    Attached Files:

  2. dadofive

    dadofive Private E-2

    Here is the RootRepeal log.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We cannot continue until you attach the requested log from MGtools which is the MGlogs.zip file in your root folder.

    Then also do the below.

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  4. dadofive

    dadofive Private E-2

    Here are the files you asked for. I'm running Windows XP Pro, SP3. Thanks for anything you can do.
     

    Attached Files:

  5. dadofive

    dadofive Private E-2

    Not sure if this relevant, but machine just "blue screened". Here is the info from the MS Error Report:
    Error Signature:
    BCCode : 1000008e BCP1 : C000001D BCP2 : 89CDB852 BCP3 : 805511B0
    BCP4 : 00000000 OSVer : 5_1_2600 SP : 3_0 Product : 256_1

    Following files will be included in this error report:
    C:\DOCUME~1\Steve\LOCALS~1\Temp\WER9e80.dir00\Mini121910-01.dmp
    C:\DOCUME~1\Steve\LOCALS~1\Temp\WER9e80.dir00\sysdata.xml
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run MGtools in normal boot mode and attach that log. A log from safe boot mode is not at helpful as it does not show us what we need to know..... and that is, what your PC is doing in normal mode. Also the log you attached is from 9 days ago. We need current logs.

    Do not power down or otherwise reboot your PC after attach the new log from MGtools.
     
  7. dadofive

    dadofive Private E-2

    OK, here it is. Sorry about that.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - .DEFAULT User Startup: wiero.exe (User 'Default user')
    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. dadofive

    dadofive Private E-2

    I've done as you requested. Things seem to be fine, but they usually do after the cleaning process. The problems would gradually resurface after a few days or more. Also, I was running the latest McAfee, subscription basis, at the time of the infection and it never caught it, nor did it find it while it was on the machine. I unistalled it during the cleaning process. Should I reinstall it or use something else/better? Thanks so much for your help.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Security begins and ends with you. Things you do ( or do not do ) can have more of an effect than you think. Yes you need antivirus, antispyware, and firewall, but if you are not careful, you will still get infected.

    One malware file is still on your PC. See if you can find and delete the below file. Then reboot. After reboot, make sure that it has not come back. Also make sure nothing similar returns in its place


    c:\documents and settings\Default User\Start Menu\Programs\Startup\wiero.exe


    Also McAfee did not cleanup after itself when uninstalled. You need to do the below.

    Open a command prompt window by clicking Start, Run, and enter cmd and click OK. If the window opens type each of the below commands in. Follow each by the enter key. Note there are spaces after the sc and after the stop and after the delete.

    sc stop 0053141292718277mcinstcleanup
    sc delete 0053141292718277mcinstcleanup

    Then so we can make sure that all is good, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. dadofive

    dadofive Private E-2

    I have done what you asked. Everything seems to be working just fine right now. But, as I said that was always the case after a cleaning, then it would rear it's ugly head again eventually. I'm optimistic, thanks to you, that it's gone now. I am careful about what i do and where i go. I have several machines and have been on the Internet since the 90's and this is the first infection. Thanks again for your help.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you are clean now.

    Yes but then those would be new infections.

    That's a good start, but you need much more as the link in the below final steps will tell you. You need an antivirus, antispyware, and a real firewall. The Windows firewall is totally inadequate. In addition you need to have a few other additional tools installed to help protect you. For example, from the link below, I suggest that you install SpywareBlaster and also Spybot. With Spybot, DO NOT use Teatimer. Just use the SDhelper ( bad download blocker ) and also use the Immunization feature.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. dadofive

    dadofive Private E-2

    One more thing please. During this infection the "Whitesmoke Translator" was installed on my machine. I can't find anyway to unistall it and I see it's in my Startup. Any help would be appreciated.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the below file then reboot. Make sure it is gone.

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launch Whitesmoke Translator.lnk
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds