Possible Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jakerod, Aug 9, 2012.

  1. Jakerod

    Jakerod Private E-2

    A few weeks ago I started getting a BSOD with Photoshop and then realized that other Adobe products had the same problem. I posted about that in another forum but decided to do a virus scan just to be safe. Norton found nothing. I heard about Malwarebytes and did a scan with that and it found 2 files I believe which I tried to have it remove to no avail.


    Problems I have been noticing:

    1.) Random sounds playing from Host Process for Windows Service.
    2.) My screen doesn't seem to shut off at the same time it used to.
    3.) My desktop icons keep getting realigned to the left and jumbled with no order that I am aware of. Automatically arrange isn't checked.
    4.) During the process of trying to find out about the random sounds playing from Host Process for Windows Service, whenever I clicked what seemed to be a useful link I got directed to some Hotmail and/or Microsoft website. When I was trying to get Defogger I had a similar issue. I eventually had to resort to going to a different computer, downloading it, and then emailing it to myself because every download link I could find redirected me to the hotmail page. I was also redirected for some of the other tools but was able to find download links for them.
    5.) Additionally, I uninstalled Norton at some point because I thought it may have been affecting driver installation. That may have been a bad idea. It was after that that Malwarebytes noticed the trojans but for all I know it could've occurred before. When I went to reinstall Norton it tells me I need to restart. I restart, it tells me the same thing. I restart again and it just keeps telling me the same thing. Sorry for my stupidity on that part.

    I do believe I have followed your Read and Run First procedures correctly and the logs are attached. If I did something wrong please let me know. And thank you for your assistance.
     

    Attached Files:

  2. Jakerod

    Jakerod Private E-2

    It won't let me edit my post. Sorry about that. Some additional information I thought of.

    Additionally, a night or a few nights before the BSOD my computer just randomly shut down. I was working on a project for a game and I think stopped to browse the internet. It suddenly asked me if I wanted to save the project I was working on and then restarted or shut down the computer, can't remember which one. I found it odd but Norton didn't give any warnings of anything and I thought it was possible I had accidentally hit alt+f4 or something like that and done it myself.

    So timeline of events:
    1.)Computer operating fine.
    2.)Computer randomly shuts down or restarts
    3.)BSODs from Adobe Photoshop CS4
    4.)BSODs from other Adobe products (probably started occurring the same time as #3 but I rarely use my other adobe products)
    5.)Began reading about possible solutions and stupidly removed Norton
    6.)Installed Malwarebytes and it detected the Trojans, were not removable.
    7.)Began noticing Host Process Sounds and computer screen problem.
    8.)Desktop Icon Rearrangement

    Hotmail problem began occurring somewhere in the middle of all of that while I was trying to find BSOD solutions. I had assumed it was just because the forum required log in but I'm not so sure about that now.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  4. Jakerod

    Jakerod Private E-2

    Thank you for your help. The log is attached.

    Another possible problem stemming from all this is that I just noticed that my clock on the computer is 1 hour ahead but the time zone is right. Not a big deal or anything but I've been trying to give as many details as possible in case something like that can help identify the problem.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------------------------

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    • Now re-run RogueKiller - no fix just a scan and attach the log.
    • Re-run FRST - no fix, just a scan and attach the log.
    • Let me know how things are running at this point.
     

    Attached Files:

  6. Jakerod

    Jakerod Private E-2

    Thanks again. The logs are attached.

    As of the last restart, my icons still aligned over to the left and my clock is now 3 hours ahead (which I can change but will leave for the time being).

    Computer has only been going for a few minutes since the last scan you told me to do so I don't know about the random sounds yet.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rerun TDSSKiller and have it fix this that you previously skipped:

    Re run again and attach new log.


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this 1 detection:
    • [ZeroAccess] HKCR\[...]\InprocServer32 : (C:\Users\Jake\AppData\Local\{c614d3bf-243a-3fd7-a4fd-36cd3756874b}\n.) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    • Reboot the machine.
    • Re run RogueKiller - no fix just a scan and attach log
    • Now run FRST again - no fix just a scan and attach log.
     
  8. Jakerod

    Jakerod Private E-2

    My only option for this is to Skip, Copy to Quarantine, or Delete. Which one of these should I select?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Quarantine or delete. ;)
     
  10. Jakerod

    Jakerod Private E-2

    Thanks. I chose delete.

    I had done an extra Scan with RogueKiller last night (will explain in a second) so my first log from today is the one with the [3] in it. I'm not sure if you needed both [4] and [5] but I uploaded them both. I will upload the TDSS one in a separate post.

    My desktop has gone back to normal. I haven't heard the random sounds since yesterday morning I don't think. The clock is still terribly off but I don't know if that will fix itself. When I did the RogueKiller scan after choosing to delete the file it didn't show back up. Thanks again.

    Regarding that extra scan. My RogueKiller keeps saying it isn't updated and would you like to go to the website to update it. If I click yes it takes me there but I don't see a download link anywhere. It says "Download:" but then the area after it is just blank. Plus the website is in French which doesn't help although I do understand a little French. Guess I could use google translate but the download link still wouldn't be there. I accidentally did an extra scan at some point while trying to update.
     

    Attached Files:

    Last edited: Aug 11, 2012
  11. Jakerod

    Jakerod Private E-2

    TDSS Killer log is attached. Others are in the post below.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run HitmanPro please and attach the results.
     
  13. Jakerod

    Jakerod Private E-2

    Here is the log. My clock seems to be correct now.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------------------------

    Now run FRST again, just a scan, no fix and attach log.
     

    Attached Files:

  15. Jakerod

    Jakerod Private E-2

    Logs attached. Desktop is still fine. Computer clock is now 2 hours ahead again. I think it did that after the last frst scan but it might've been after the frst fix.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ready for final steps?
     
  17. Jakerod

    Jakerod Private E-2

    I seem to be I guess. I would imagine you wouldn't ask me if I weren't. The only problem left is really the clock which I can change myself.

    Also there are 3 "hidden" files on my desktop. 2 that are desktop.ini and one that is a word document I think I deleted a while back. Can I remove those? I tend to keep Show Hidden files on but they were not present until I began the malware removal process.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The hidden files should be hidden again once you follow final steps. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  19. Jakerod

    Jakerod Private E-2

    Thanks for the help.

    At some point during all of that, even though I did not disable hidden folders, the hidden folders went away as well as the shortcuts for several of those programs that I had to download for this even though I don't believe I told anything to remove them.

    Everything seems okay though. I tried to reinstall Norton but that didn't work so I chose a different one instead and now Norton Downloader won't shut up every time I restart my computer.

    Thanks again for all your help. If something comes up that I think is related to this I guess I will either post here or make a new topic depending on which seems warranted according to the rules here.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds