Trojan downloader

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pitty238, Dec 2, 2009.

  1. Pitty238

    Pitty238 Private E-2

    Im having problems with a trojan downloader that continues to come back after removal. My hard line for internet no longer works and im having to use wireless. The virus also opens 3 websites upon starting google. Thanks for the help.

    Patrick
     

    Attached Files:

  2. Pitty238

    Pitty238 Private E-2

    SAS logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this a different computer than the one that Kestrel is working with you HERE?
     
  4. Pitty238

    Pitty238 Private E-2

    Yes that was for a friend, but now I have somehow gotten a similar virus
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK, good to know....then we will get to your problems as we work thru our queue. ;)
     
  6. Pitty238

    Pitty238 Private E-2

    Dont mean to sound like im complaining, I was just curious about the time for the que. I know there are a lot, I apologize if this comes off the wrong way. Thanks
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    TimW Has been extremely busy on and offline. Could you attach the other requested log for him? ---> C:\mglogs.zip into your next reply please?
     
    Last edited: Dec 14, 2009
  8. Pitty238

    Pitty238 Private E-2

    I didnt even realize I had posted the wrong logs. Thanks for the heads up. Sorry about that.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well now that I am online and still off work with a cold I may as well go through your logs. Give me a little while and I'll get back to you as soon as I can.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    ... and whilst I do that.. you can do this:

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Removal by which software? What is detecting the trojan?

    1. Ensure that MGTools.exe is indeed directly on your C Drive where it should be.

    2. Also I need you to use MSConfig to put the machine into normal start up mode if it isn't already before we continue.

    3. You also have Spybot S&D's teatimer function running and our procedures request that you do not:

    How to disable Spybot's TeaTimer

    4. Please go to add/remove programs and uninstall the below out of date java:

    • Java(TM) 6 Update 16

    5. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    Folder::
    c:\program files\Personal Guard 2009(2)
    C:\Documents and Settings\Patrick\Local Settings\temp\clclean.0001.dir.0000
    C:\Documents and Settings\Patrick\Local Settings\temp\clclean.0001.dir.0001
    C:\Documents and Settings\Patrick\Local Settings\temp\plugtmp
    
    File::
    C:\DOCUME~1\Patrick\LOCALS~1\Temp\clclean.0001
    C:\WINDOWS\system32\RENCA.tmp 
    C:\WINDOWS\system32\REN183.tmp
    C:\WINDOWS\system32\REN184.tmp
    C:\WINDOWS\system32\RENC9.tmp
    C:\WINDOWS\TEMP\WFV9.tmp
    C:\Documents and Settings\Patrick\Local Settings\temp\clclean.0001
    C:\Documents and Settings\Patrick\Local Settings\temp\IMT14.xml
    C:\Documents and Settings\Patrick\Local Settings\temp\IMT15.xml
    C:\Documents and Settings\Patrick\Local Settings\temp\IMT16.xml
    C:\Documents and Settings\Patrick\Local Settings\temp\IMT7E.xml
    C:\Documents and Settings\Patrick\Local Settings\temp\IMT7F.xml
    C:\Documents and Settings\Patrick\Local Settings\temp\IMT80.xml
    C:\Documents and Settings\Patrick\Local Settings\temp\JET5975.tmp
    C:\Documents and Settings\Patrick\Local Settings\temp\~ROMFN_0000027C
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    6. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    Code:
    C:\Documents and Settings\Patrick\Local Settings\[B]temp[/B]
    C:\WINDOWS\[B]TEMP[/B]
    7. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    8. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. and the new log from running SAS.

    9. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  12. Pitty238

    Pitty238 Private E-2

    Thank you for the quick response, im sure you know about the combofix problems, so ill complete it when they fix the bug. Thanks again for the help.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    let's go another way round considering Combofix is out of action. There is a beta version available but we wont use that unless we need to.

    1. Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.



    2. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    Code:
    C:\Documents and Settings\Patrick\Local Settings\[B]temp[/B]
    C:\WINDOWS\[B]TEMP[/B]
    3. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    4. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. and the new log from running SAS.

    5. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
    Removal by which software? What is detecting the trojan?
     
  14. Pitty238

    Pitty238 Private E-2

    Ok...So i tried to run the avenger while disabling all scans before running. When i ran it I got this message form "on access scan":

    Name: C:/CLEANUP.exe
    Detected as: ZapChast.gen
    State: Deleted

    This happens each time i try to run avenger, it restarts and no logs are reproduced. I did everything else on the list. Ill attach the SAS which found nothing and the MG logs. Also on a second note, since this all started my touch pad mouse no longer works and the LAN connection i used to have for my hard line internet is gone. Wireless still functions, but it doesnt register any ethernet cable. Thanks again for the help
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is just a false positive from your antivirus (Mcafee)


    You failed to follow my previous instructions about uninstalling the version you have, and reinstalling the new version which is available, and which I linked you to. You need to do what I asked and follow those instructions.

    See my post # 10

    The files that were in my previous avanger script weren't really problems as such, just temp files I wanted gone... so for now just update SUPERantispyware and also please explain to me something. When you first came here you said:

    Where exactly is it finding the threat? I would like to know the exact file and file path. Are you having google redirect issues or malware problems still, or are the only problems that remain your LAN conncetion and your touch pad mouse?

    Thanks
    Kes13!
     
    Last edited: Dec 17, 2009
  16. Pitty238

    Pitty238 Private E-2

    Sorry about the SAS thing, I did not see post #10 as it was separate from the other instructions. I uninstalled and downloaded the version that you linked and have run a complete scan with attached logs. I also went back and found the original logs from both SAS and malwarebytes when this problem started that were run within 3 hours of each other. I also located the avenger logs which are now attached.

    As for the current situation, The problem occurred when I ran internet off of the hardline. I take the computer to school, and when I connected to the university wireless no problems occurred. At that point I thought maybe it was my internet provider, so I plugged the computer into the ethernet line at school and the same problems happened again. Then at some point I restarted and the LAN connection no longer worked (or existed) as well as the touch pad. So as it stands it hasnt happened for a while, but I havent been using a hard line or this computer for fear of messing it up further. Thanks again.

    Note: My provider was comcast if you needed that
     

    Attached Files:

  17. Pitty238

    Pitty238 Private E-2

    avenger logs
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think focus is being lost a little. Let's return to your original problem, you said:
    I would like you to answer the below questions for me so that we don't waste more time:

    Are you still having problems with a trojan downloader that keeps returning? If so, which software is detecting it? If Macafee you MUST give me the full file and file path of where it is being found (I did ask you to tell me more about the trojan on a couple of occasions)

    So do not attach any more logs or do anything else until you have let me know about the above.

    Thanks Kes13!
     
  19. Pitty238

    Pitty238 Private E-2

    Ok, I thought I had been answering the question, but maybe im just misreading. The software is no longer picking up the trojan (with the exception of a new one SAS foudn last night? in the logs). When I had not heard from TimW I system restored so maybe that did something. However, the effects have lasted in the mouse pad and ethernet no longer working. I hope I am answering things correctly, I can tell you are becoming agitated and I apologize. I do greatly appreciate the help.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks for explaining it in more detail. :) I am certainly not becoming agitated, I have the patience of a saint heh. I just wanted us to cut to the chase so to speak, I am not seeing any malware in your logs. I want you to open up both MBAM and SAS, update > scan > and fix anything the programs detect.

    Attach these new logs into your next reply.

    After that, if they are finding no threats, then I think I will be giving you final steps, and that any remaining problems you have will have to be worked out in the software forum.

    Thanks
    kes13!
     
  21. Pitty238

    Pitty238 Private E-2

    Thanks for the help
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is any other software you have installed detecting any threats? Also, to be absolutely sure, is this still happening?
     
  23. Pitty238

    Pitty238 Private E-2

    Nope software is not detecting any threats. As for the websites popping up, as I suggested in the previous post #16, it would only happen with connecting to an ethernet hardline. Never while on wireless. This occurred on two separate internet providers and im unable to connect to a hardline at this time.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your logs are clean. Any other issues you are having will have to be worked out in the other areas of the forum :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds