trojan HELP!

Discussion in 'Malware Help (A Specialist Will Reply)' started by levit8, Feb 16, 2011.

  1. levit8

    levit8 Private E-2

    Cannot remove this thing.

    Tried avg free, malwarebytes. Then tried some combofixes

    nod 32 results:
    2/17/2011 11:31:53 AM Startup scanner file C:\WINDOWS\system32\Drivers\NDIS.sys a variant of Win32/Kryptik.ABX trojan unable to clean


    Any help will be appreciated, but I'm on a short deadline.

    Cheers
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. levit8

    levit8 Private E-2

    Malware bytes isn't picking up the virus. Only avg & nod32.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Regardless. I want to see all the logs from running our procedures, including that of Malware Bytes. ;) If you are on a deadline it would be best to follow instructions and attach all of the requested logs once you have run our procedures.
     
  5. levit8

    levit8 Private E-2

    i don't live close to the infected machine, but I'll get a malwarebytes log for you.

    thanks for the quick reply.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to get all of the requested logs or you will be wasting your time. We need the logs from all of the below that were run in the order requested in the READ & RUN ME. We did not ask you to run a CFScript.txt fix with ComboFix so are you working on another site?
    • SUPERAntiSpyware
    • Malwarebytes
    • ComboFix
    • RootRepeal
    • MGtools
     
  7. levit8

    levit8 Private E-2

    Thanks for your advice. I've followed all the read & run instructions to the letter.
    Here are three of the logs. mgtools to follow.


    ps. this site is awesome.

    thanks guys.
     

    Attached Files:

  8. levit8

    levit8 Private E-2

    mgtools
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not quite. ;) You put ComboFix in an improper location. You have it here:

    c:\documents and settings\workexp\Desktop\pc restore\tools\ComboFix.exe

    You need to move it driectly to the Desktop folder not a subfolder of anything on your Desktop.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. levit8

    levit8 Private E-2

    Here are the two logs you asked for.

    I am running a nod32 scan to see if it still shows up.

    thanks
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ad-Aware SE Professional <--- Outdated and ineffective, might as well uninstall it!

    Delete these folders:
    • c:\documents and settings\workexp\Local Settings\Application Data\ICS
    • c:\documents and settings\All Users\Application Data\MFAData
    • c:\program files\Enigma Software Group

    Delete this file:
    • C:\u7f516u2.bin

    Could you please get this: 2515693230 into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip

    Also let us know if NOD is still detecting anything or not.
     
  12. levit8

    levit8 Private E-2

    I deleted all the folders you requested and the .bin file.

    the paste and run wouldn't produce a zip file.

    attached are the nod results.
     

    Attached Files:

  13. levit8

    levit8 Private E-2

    and I unistalled ad-aware.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to virustotal and upload the following files for analysis, and let me know the results.

    C:\Documents and Settings\workexp\Templates\2515693230
     
  15. levit8

    levit8 Private E-2

    Thanks for your persistence.

    here it is
     

    Attached Files:

  16. levit8

    levit8 Private E-2

    I don't understand why the first nod scan found one virus on friday, then found three on monday with the machines turned of all wkend.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What it is finding is not a problem now considering it is detecting it in Combofix's back up folder and in system restore. Both of which will no longer be detected after you have followed final steps.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. levit8

    levit8 Private E-2

    Thanks a million!!:-D
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds