Trojan and redirect help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Computermessed, Jul 28, 2011.

  1. Computermessed

    Computermessed Private E-2

    Hi,

    About a week ago I started to have browser redirection problems (both IE and Firefox), and did a few things before I found your site.

    I downloaded and ran ESET Online Scanner (see ESET online run1 log attached). This showed a Win32/Kryptik.QRB Trojan and Win32/TrojanDownloader.Tracur.F Trojan which it appeared to delete. I then decided to restore from a restore point about a month ago (not sure if this was a good idea?).

    I then found your site, and completed all the steps to the walkthrough (see attached logs):

    SuperANTIspyware – did not find anything

    Malwarebytes – did not find anything

    Combofix – hung up on Stage 4 and would not go further. I let it run for over an hour. Closed the window and tried again. Still hung on Stage 4 for over an hour. I could not find a log from the sessions.

    Rootrepeal – I am running Windows 7 x64 so did not run

    MGTools – ran fine, log attached.

    After running the tools, I ran ESET Online Scanner again (see ESET online run2 log attached in post #2) for the heck of it and it found JS/Agent.NDJ Trojan and Eicar test file, both apparently removed. Not sure why the other tools didn’t detect this?

    I am worried that there is more hiding somewhere!

    Thanks for your help. I appreciate your time!
     

    Attached Files:

  2. Computermessed

    Computermessed Private E-2

    Here is the ESET #2 run attached. Thanks!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. What malware issues are you having, if any?
     
  4. Computermessed

    Computermessed Private E-2

    Hi TimW,

    Thanks for the quick response.

    I had not connected to the internet with the infected computer since the initial ESET scan. I just browsed with IE and firefox for around 5 min and had no google redirect problems (I had a redirect every other link before).

    I do get a "The system can not find the specified file" error message on startup, which I did not get before the anti-spyware scans and reverting to the restore point. Could this be linked to Malware? Is there any way to diagnose this and fix?

    Also,

    1) Is there anyway to see if the Trojan's found by ESET:

    Win32/Kryptik.QRB Trojan
    Win32/TrojanDownloader.Tracur.F Trojan
    JS/Agent.NDJ Trojan

    compromised any files or information?

    2) I was thinking about restoring the computer to factory condition since I have my data backed up and haven't installed many programs. Would this give me another level of protection or not really help?

    Thanks!
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    A clean install is always the safest route to take, but if you are not having any issues, you may want to forgo that option. You need to tell me what the message is on start up so we can see about removing that.
     
  6. Computermessed

    Computermessed Private E-2

    Hi, the message at start up (after logining in and getting to the desktop) was a box with error at the top and a "X" within a red circle on the left hand side of the box with the words "The system can not find the specified file" to the right of the red circle with "X". It seems like it was associated with OpenOffice, and after I uninstalled OpenOffice, the message no longer appears.

    I have not experienced any odd behavior since running ESET and the MajorGeeks scans (no browser redirects, no lag in tasks). I still can not get Combofix to run (gets stuck in Stage 4).

    Do you reccomend anything else? Is there a way to figure out what the malware did when it was active? Thanks for the help, and maintaining all the great info on this site.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's hard to say what the malware may have done to your system, though it is probably responsible for corrupting your Open Office software. But if you are no longer having issues, then you can finish up with these instructions:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds