Stuck with 2 work computers filled with trojans spamware

Discussion in 'Malware Help (A Specialist Will Reply)' started by chrisdab, Mar 16, 2007.

  1. chrisdab

    chrisdab Private E-2

    I have been trying to fix 2 work computers at a company I just joined because I am the only one there who is considered the "tech" guy. Both computers were filled with trojans and spyware. Well today I blue screened one computer because I tried to install SP2 while spyware was on the computer. I have to now reinstall windows to fix this, so I realize I cant do this on my own and I need some help.

    My goal is to clean out the 2nd computer which is a windows 2000 SP4. From what I have heard, spyware had been on these computers for up to a year or more, using mailers to send out email, opening backdoors, and asking to install more malware. I had installed Nod32 antivirus, AVG anti-spyware, spyware blaster, spyware guard, and spybot. I tried installing sunbelt kerio personal firewall but had to uninstall because it couldnt load. Two programs I will plan to install were codestuff starter and snoopfree privacy shield. I also did online scans with Kasperksy Online and eTrust Antivirus Scanner.

    One problem with all this is I tried going into safe mode but couldnt, no matter how often I tried pressing F8. I am not sure what the issue was that wouldnt let me start in safe mode, but because of that, all my protection software installs are suspect and any scans I do arent as effective. I dont get much time on these computers because I am out in the field.

    I wrote down some virus software that persisted through many of these scans I did. Some may have been deleted over time and I will post HJT logs and virus scan logs tomorrow if someone requests it.

    win32/trojandownloader.busky trojan
    downloader.small.efh
    trojan.agent.ady
    worm.zhelain.d
    adware.gator
    worm.zhelatin.al
    proxy.small
    proxy.slapper.p
    adware.deluxecommunications
    worm.banwarum.f
    adware.bookedspace
    backdoor.sdbot.bfn
    win32/adware.relevant -rk32.exe
    ultimate fixer

    I was able to install windows updates in windows 2000 after I deleted some viruses, so I was hoping to do the same in windows xp. It went bad so now i am hoping to do more good than harm.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Below are our required malware cleaning procedures. Note, since you are having problems with safe boot mode, I suggest that where we specify running in safe boot mode during the procedure that you just ignore it and run everything from Normal boot mode.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. chrisdab

    chrisdab Private E-2

    this post contains:
    runkeys.txt
    newfiles.txt
    hijackthis.log
     

    Attached Files:

  4. chrisdab

    chrisdab Private E-2

    I didnt have time to do these scans today:

    # Bitdefender - from step 6
    # Panda Scan - from step 6

    I did post logs from
    AVG antispyware
    a-squared
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The procedure is designed to be run in the order written. Not running these scans as requested only makes the scans run afterwards (GetRunKey, ShowNew, and HJT) not as useful. It makes it more difficult to resolve your problems and makes manual steps for us longer to complete. We will not have the time to fix hundreds of PCs every week if directions are not followed because it makes our jobs harder and requires more time which we do not have.

    You also had AVG Antispyware ignore what it found which is again a waste of time. Now you need to run it again and have it fix what it finds and attach a new log. Then you need to run BitDefender and PandaActiveScan and attach their logs.

    Afterwards you will need to attach new logs from GetRunKey, ShowNew and HJT.


    You have a lot of malware!!! All the steps are necessary.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also make sure you follow the directions in step 6 where it specifies to uninstall your old Sun Java version and install the current version from the link given. You are using a version that is at least 3 years out of date. Without the new version, the online scans may not even run.

    It also does not look like CCleaner was run or perhaps it just did not clean your Temp folders. Did you change the options? There are files in your Temp folder from as far back as March 10th and some of the files are malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds