Trojan Attack!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Simon Pc is dying, Jan 12, 2008.

  1. Simon Pc is dying

    Simon Pc is dying Private E-2

    Hello all, sorry to trouble you but I could really use a hand with this one.

    At some point within the last 24 hrs, my AVG went a bit spastic with infection notices about a trojan.GIT. Since, I have scoured the forum and used a plethora of anti-virus, spyware, malware etc. tools** in accordance with the advice given in other threads of a similar nature (this is usually my first and last step in curing such ailments). Sadly, my computer is still running at a barely functioning speed and the task manager gives no hints as to where this processing power is going...

    Safe Mode is also affected by this slow performance and running programs such as spybot s&d is almost impossible in normal mode, and only just managable in safe mode (after a few hours).

    ** - including: ATF cleaner, Combofix, Killbox-beta, Procexp, Rogue Remover, SUPER Antispyware, Virtumundobegone (reported no more instances of infection), Vundofix (reported no more instances of infection).

    Without further ado, I submit my HJT log:

    Any help or advice you can offer would be much appreciated guys.:major
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read the sticky threads. You should not be posting HijackThis logs.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Simon Pc is dying

    Simon Pc is dying Private E-2

    Hi there, sorry for the delay - I had to work yesterday.
    Have followed the instructions as per, and attached are the logs as requested - although I had slight trouble with the AVG log (I have included the history log, but did not manage to locate a report after the scan had been run).

    Thanks for your help,
    Simon.
     

    Attached Files:

  4. Simon Pc is dying

    Simon Pc is dying Private E-2

    AVG history log
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a log from AVG Antispyware and it is not a log we wish to see. You need to installed and run AVG Antispyware as requested in the READ & RUN ME.

    You need to attach the log from ComboFix.
     
  6. Simon Pc is dying

    Simon Pc is dying Private E-2

    Sorry, not trying to be a pain but I think this section of the "READ & RUN ME" is outdated as I cannot find the buttons it mentioned nor can I seem to figure out how to save/export a report. I have attached the combo fix log.

    Any ideas on how to get the report?

    ["READ & RUN ME"]
    "
    # Under How to scan?

    * All checkboxes should be ticked.

    # Under "Reports" Select "Automatically generate report after every scan" Also, Un-Select "Only if threats were found".
    # Under What to scan?

    * Select Scan every file

    # Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    # AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
    # Once the scan is complete do the following:
    # If you have any infections you will prompted, when prompted select "Apply all actions".
    # Next select the "Reports" icon at the top.
    # Select the "Save Report As" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
    # Exit AVG Anti-Spyware and attach the results of the AVG Anti-Spyware scan.
    "
     

    Attached Files:

  7. Simon Pc is dying

    Simon Pc is dying Private E-2

    Ok, think the report is now, as of version 7.5, exported by a keyboard shortcut ctrl+S (I'm sure there is a button lying around somewhere..).

    Have attached past two complete tests.
     

    Attached Files:

    • AVG.zip
      File size:
      1.3 KB
      Views:
      1
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What program are you running???? Give the exact name?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now we need to use a new tool.
    • Download and save to RenV.exe
      from following link to Desktop (must be on the Desktop)
    • Now Copy the bold text in the below quote box to notepad. Save it as Log.txt to your desktop. (It must be on
      your Desktop).
    • Now using your mouse, drag Log.txt onto RenV.exe
    • When finished, RenV.exe will produce a new log names Log.txt on your Desktop I will ask for this log later.
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and
    select the following lines but DO NOT CLICK FIX until you exit all browser sessions
    including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\WINDOWS\system32\gebcb.exe
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O2 - BHO: (no name) - {B8DD76AA-52BD-4298-A978-598CB40E695F} - (no file)
    O2 - BHO: (no name) - {D4576C73-52BD-4401-B966-5A128C4433D4} - (no file)
    O2 - BHO: (no name) - {D62A8AF0-607B-490C-8378-C029D9ED443F} - (no file)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
    O20 - Winlogon Notify: cbxuvuv - C:\WINDOWS\

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46,
    and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • Log.txt from RenV
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. Simon Pc is dying

    Simon Pc is dying Private E-2

    Have followed your instructions, no-more pop-ups now and since running a chkdsk repair, defrag and your instructions, computer seems to be performing ok again.

    Some of the files couldn't be found - and subsequently weren't deleted - whilst I followed the instructions set out in your last post. I think AVG may have automatically removed them - I'm not missing anything crucial to system running am I?

    Thanks for everything, you've been a great help!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are still infected. Looks to me like you did not follow the instructions. Did you drag Log.txt ontop of Renv.exe as requested? Based on the log you just attached it looks like you did not.

    You also need to attach the MGlogs.zip log I requested in my last message. But first do the steps over again since it looks to me like you did not do them properly or you had somekind of problem and did not mention it.
     
  12. Simon Pc is dying

    Simon Pc is dying Private E-2

    hi, followed the instructions again - sorry, forgot to run "getlogs.bat". have attached logs.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like we are almost finished.


    Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on
    your Desktop). [code
    C:\Program Files\QuickTime\qttask .exe [/code]
    • Now using your mouse, drag Log.txt onto RenV.exe
    • When finished, RenV.exe will produce a new log names Log.txt on your Desktop
    • Attach this new Log.txt file.
     
  14. Simon Pc is dying

    Simon Pc is dying Private E-2

    ok, here is the log as requested
     

    Attached Files:

    • log.txt
      File size:
      277 bytes
      Views:
      3
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I had a mistake in my last fix which cause it not to work. Sorry about that. Please use this one.

    Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on
    your Desktop).
    Code:
    C:\Program Files\QuickTime\qttask    .exe
     
    • Now using your mouse, drag Log.txt onto RenV.exe
    • When finished, RenV.exe will produce a new log names Log.txt on your Desktop
    • Attach this new Log.txt file.
     
  16. Simon Pc is dying

    Simon Pc is dying Private E-2

    Not a problem.

    Here is log file as requested.
     

    Attached Files:

    • log.txt
      File size:
      277 bytes
      Views:
      1
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not look like the step is working for you. Just delete the below file yourself.
    Code:
    ----a-w   155,648 2008-01-12 11:43:24  C:\Program Files\QuickTime\qttask    .exe
    Then tell me how things are working.
     
  18. Simon Pc is dying

    Simon Pc is dying Private E-2

    Hello, apologies for the delay in response - work related issues again.

    Have managed to successfully locate and delete file.
    Things seem to be running relatively smoothly, aside from one minor problem:

    Since performing the spyware removal procedures, windows xp no longer shuts down properly. Upon clicking "start" "shutdown", the cursor changes to its loading graphic and explorer hangs until I ctrl+alt+del my way out of windows.

    Could this problem be related or shall I continue to seek advice in a different forum (i.e. is this not malware related anymore?)

    Thanks for your help
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    More than likely this is not malware but let's check for rootkits just to be sure.

    Run this Using Sophos Anti-Rootkit and attach the log.

    Also answer another question, if you boot in safe mode, do you also have a problem with Windows shutdown.
     
  20. Simon Pc is dying

    Simon Pc is dying Private E-2

    hmm...scan showed nothing (have attached log) and problem does not occur in safe mode.

    Any ideas / suggestions?
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try one more thing before I have to send you off to the Software Forum.


    Click Start, Run, and enter sfc /scannow and click OK. This will run System File Checker to look for missing or corrupt system files. It may ask for your Windows CD if it finds problems it needs to fix. Be prepared to put in your CD.

    Let me know what happens after running this.

    Since the problems do not appear in safe mode, something that gets loaded during normal bootmode appears to be causing you problems with shutdown.
     
  22. Simon Pc is dying

    Simon Pc is dying Private E-2

    sadly no problems discovered when the sfc ran.
    I shall move on to a different forum.
    Thanks for all your help - actually just used your advice yesterday when my housemate got the same vundo infection.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Note that no two Vundo infections are ever exactly the same. They may have some common items like DLL file names and cause similar problems, but each will normally deposit different file names on your hard disk. And there are many many different versions of Vundo around too. Your friend should really perform the READ & RUN ME and attach the logs in his own thread.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds