Superantispy now no web access

Discussion in 'Malware Help (A Specialist Will Reply)' started by chartist, Nov 15, 2010.

  1. chartist

    chartist Private E-2

    I ran Superantispy on my daughters laptop as the browser had been attacked and it quarantined 4 trojan
    Trojan.agent/GEN-DWM (Fake)
    Trojan.agent/GEN-Fake (Shell)
    Trojan.agent/GEN-Fuffan
    Trojan.SVCHost/Fake

    and now I have no internet access. The wireless connection is fine

    If I restore the Trojans it all works again


    Please help

    Andy
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I need to know the locations of the threats found, the exact file paths please.
     
  3. chartist

    chartist Private E-2

    Ok, is there an easy way for me to get this? I can see all the paths in the quarantine window on superantivirus. is there a report or anything? thanks so so much for your help...in anticipation! Andy
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  5. chartist

    chartist Private E-2

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 11/15/2010 at 09:42 AM

    Application Version : 4.45.1000

    Core Rules Database Version : 5860
    Trace Rules Database Version: 3672

    Scan type : Complete Scan
    Total Scan Time : 00:57:42

    Memory items scanned : 268
    Memory threats detected : 3
    Registry items scanned : 6351
    Registry threats detected : 3
    File items scanned : 67184
    File threats detected : 10

    Trojan.Agent/Gen-Fake[Shell]
    C:\DOCUMENTS AND SETTINGS\STEPHANIE\APPLICATION DATA\MICROSOFT\WINDOWS\SHELL.EXE
    C:\DOCUMENTS AND SETTINGS\STEPHANIE\APPLICATION DATA\MICROSOFT\WINDOWS\SHELL.EXE

    Trojan.SVCHost/Fake
    C:\DOCUMENTS AND SETTINGS\STEPHANIE\APPLICATION DATA\MICROSOFT\SVCHOST.EXE
    C:\DOCUMENTS AND SETTINGS\STEPHANIE\APPLICATION DATA\MICROSOFT\SVCHOST.EXE
    [svchost] C:\DOCUMENTS AND SETTINGS\STEPHANIE\APPLICATION DATA\MICROSOFT\SVCHOST.EXE

    Trojan.Agent/Gen-DWM[Fake]
    C:\DOCUME~1\STEPHA~1\LOCALS~1\TEMP\DWM.EXE
    C:\DOCUME~1\STEPHA~1\LOCALS~1\TEMP\DWM.EXE
    [Load] C:\DOCUME~1\STEPHA~1\LOCALS~1\TEMP\DWM.EXE
    C:\DOCUMENTS AND SETTINGS\STEPHANIE\LOCAL SETTINGS\TEMP\DWM.EXE

    Malware.Trace
    HKU\S-1-5-21-1430034154-126857994-2976543226-1008\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON#SHELL

    Trojan.Agent/Gen-Fuffan
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{4488DE73-09D1-43E5-A8F7-F1EDDB4EB85D}\RP551\A0060535.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{4488DE73-09D1-43E5-A8F7-F1EDDB4EB85D}\RP551\A0060537.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{4488DE73-09D1-43E5-A8F7-F1EDDB4EB85D}\RP554\A0061233.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{4488DE73-09D1-43E5-A8F7-F1EDDB4EB85D}\RP554\A0062248.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{4488DE73-09D1-43E5-A8F7-F1EDDB4EB85D}\RP554\A0062263.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{4488DE73-09D1-43E5-A8F7-F1EDDB4EB85D}\RP554\A0062307.EXE
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to foolow through with the rest of our malware removal procedures:

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  7. chartist

    chartist Private E-2

    Ok on it now thanks
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem, I'll be here waiting.
     
  9. chartist

    chartist Private E-2

    Hi, Combofix would not run saying clash with AVG being installed and running root repeal stoped saying I needed to do a chkdsk. Hope the logs help
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is this?

    • C:\WINDOWS\system32\8104297.jun

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    Java(TM) SE Runtime Environment 6 <--- uninstall this.

    Reboot the machine

    Install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how things are running
    . :)
     
  11. chartist

    chartist Private E-2

    What is this?

    C:\WINDOWS\system32\8104297.jun

    Not a clue!!!!

    Just checked internet access...it now seems to work perfectly

    Thanks so much
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like you did not allow MGTools to run to completion. It is missing a few logs. Please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip

    Tell me if you have any error messages.
     
  13. chartist

    chartist Private E-2

    Hi yes it ran to the end and I just gave you the file as was created. I am not by the computer for a few hours but will do it again later. Thanks so much
     
  14. chartist

    chartist Private E-2

    Hi here it is as promised

    The lap top is very very slow to boot up from the point of the background image being displayed to the desktop icons appearing.

    thanks so much again
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. But something is using a lot of your system resources:
    Code:
    Total Physical Memory    1,024.00 MB    
    Available Physical Memory    230.70 MB
    Try uninstalling AVG2011 and see if that makes a difference.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds